CVE-2024-13201 | wander-chu SpringBoot-Blog 1.0 Admin Attachment AttachtController.java upload File unrestricted upload
A vulnerability classified as critical has been found in wander-chu SpringBoot-Blog 1.0. This affects the function Upload of the file src/main/java/com/my/blog/website/controller/admin/AttachtController.java of the component Admin Attachment Handler. Performing manipulation of the argument File results in unrestricted upload.
This vulnerability was named CVE-2024-13201. The attack may be initiated remotely. In addition, an exploit is available.
The vendor was contacted early about this disclosure but did not respond in any way.