
CVE-2024-13111 – Beijing Yunfan Internet Technology Yunfan Learning Examination System JWT Token SysUserControl improper authentication
https://notcve.org/view.php?id=CVE-2024-13111
02 Jan 2025 — A vulnerability classified as critical was found in Beijing Yunfan Internet Technology Yunfan Learning Examination System 1.9.2. Affected by this vulnerability is an unknown functionality of the file src/main/java/com/yf/exam/modules/sys/user/controller/SysUserControl of the component JWT Token Handler. The manipulation leads to improper authentication. The attack can be launched remotely. The complexity of an attack is rather high. • https://github.com/qiutiandefeng/yfexam-exam/issues/6 • CWE-287: Improper Authentication •

CVE-2024-13110 – Beijing Yunfan Internet Technology Yunfan Learning Examination System Exam Answer PaperController.java, information disclosure
https://notcve.org/view.php?id=CVE-2024-13110
02 Jan 2025 — A vulnerability classified as problematic has been found in Beijing Yunfan Internet Technology Yunfan Learning Examination System 1.9.2. Affected is an unknown function of the file src/main/java/com/yf/exam/modules/paper/controller/PaperController.java, of the component Exam Answer Handler. The manipulation leads to information disclosure. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. • https://github.com/qiutiandefeng/yfexam-exam/issues/5 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor CWE-284: Improper Access Control •

CVE-2024-13109 – Beijing Yunfan Internet Technology Yunfan Learning Examination System doc.html improper authorization
https://notcve.org/view.php?id=CVE-2024-13109
02 Jan 2025 — A vulnerability was found in Beijing Yunfan Internet Technology Yunfan Learning Examination System 1.9.2. It has been rated as critical. This issue affects some unknown processing of the file /doc.html. The manipulation leads to improper authorization. The attack may be initiated remotely. • https://github.com/qiutiandefeng/yfexam-exam/issues/4 • CWE-266: Incorrect Privilege Assignment CWE-285: Improper Authorization •