Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-51369 | A vulnerability was found in wangl1989 mysiteforme 1.0 and classified as critical. Affected by this issue is the function rememberMeManager of the file src/main/java/com/mysiteforme/admin/config/ShiroConfig.java. The manipulation leads to deserialization. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. |
Fri, 10 Jan 2025 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Wangl1989
Wangl1989 mysiteforme |
|
| CPEs | cpe:2.3:a:wangl1989:mysiteforme:1.0:*:*:*:*:*:*:* | |
| Vendors & Products |
Wangl1989
Wangl1989 mysiteforme |
Mon, 06 Jan 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sun, 05 Jan 2025 09:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was found in wangl1989 mysiteforme 1.0 and classified as critical. Affected by this issue is the function rememberMeManager of the file src/main/java/com/mysiteforme/admin/config/ShiroConfig.java. The manipulation leads to deserialization. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. | |
| Title | wangl1989 mysiteforme ShiroConfig.java rememberMeManager deserialization | |
| Weaknesses | CWE-20 CWE-502 |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2025-01-06T15:56:04.087Z
Reserved: 2025-01-04T09:48:31.422Z
Link: CVE-2024-13136
Updated: 2025-01-06T15:55:39.100Z
Status : Analyzed
Published: 2025-01-05T09:15:06.320
Modified: 2025-01-10T21:01:43.337
Link: CVE-2024-13136
No data.
OpenCVE Enrichment
No data.
EUVD