A vulnerability, which was classified as critical, was found in taisan tarzan-cms 1.0.0. This affects the function UploadResponse of the file src/main/java/com/tarzan/cms/modules/admin/controller/common/UploadController.java of the component Article Management. The manipulation of the argument file leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
History

Thu, 21 Aug 2025 17:45:00 +0000

Type Values Removed Values Added
First Time appeared Taisan
Taisan tarzan-cms
CPEs cpe:2.3:a:taisan:tarzan-cms:1.0.0:*:*:*:*:*:*:*
Vendors & Products Taisan
Taisan tarzan-cms

Mon, 30 Dec 2024 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 29 Dec 2024 20:15:00 +0000

Type Values Removed Values Added
Description A vulnerability, which was classified as critical, was found in taisan tarzan-cms 1.0.0. This affects the function UploadResponse of the file src/main/java/com/tarzan/cms/modules/admin/controller/common/UploadController.java of the component Article Management. The manipulation of the argument file leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Title taisan tarzan-cms Article Management UploadController.java UploadResponse unrestricted upload
Weaknesses CWE-284
CWE-434
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published: 2024-12-29T20:00:13.083Z

Updated: 2024-12-30T16:09:52.900Z

Reserved: 2024-12-28T16:29:49.749Z

Link: CVE-2024-13022

cve-icon Vulnrichment

Updated: 2024-12-30T16:09:48.012Z

cve-icon NVD

Status : Analyzed

Published: 2024-12-29T20:15:05.980

Modified: 2025-08-21T17:34:04.890

Link: CVE-2024-13022

cve-icon Redhat

No data.