1 results (0.006 seconds)
CVSS: 6.3EPSS: 0%CPEs: 4EXPL: 1

CVE-2024-12483 – Dromara UJCMS User ID id authorization
https://notcve.org/view.php?id=CVE-2024-12483
11 Dec 2024 — A vulnerability classified as problematic has been found in Dromara UJCMS up to 9.6.3. This affects an unknown part of the file /users/id of the component User ID Handler. The manipulation leads to authorization bypass. It is possible to initiate the attack remotely. The complexity of an attack is rather high. • https://github.com/cydtseng/Vulnerability-Research/blob/main/ujcms/IDOR-UsernameEnumeration.md • CWE-285: Improper Authorization CWE-639: Authorization Bypass Through User-Controlled Key •