CVE Radar

CVE Radar Logo
CVERadar

Edition used by more than 30,000 companies in more than 150 countries.
Sign Up For Free

CVE-2024-13195

Medium Severity|Donglight
30
SVRS
9.8
CVSSv3
0.00102
EPSS
A vulnerability was found in donglight bookstore电商书城系统说明 1.0.0. It has been classified as critical. This affects the function getHtml of the file src/main/java/org/zdd/bookstore/rawl/HttpUtil.java. The manipulation of the argument url leads to server-side request forgery. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
TAGS
In The WildExploitSignature
VECTOR STRING
CVSS:3.1AV:NAC:LPR:NUI:NS:UC:HI:HA:H
PUBLICATION DATE2025-01-08
LAST MODIFIED2025-01-09

Deep CVE Analysis in Progress

The system is currently conducting an in-depth analysis of the selected CVE. This includes advanced correlation, vulnerability classification, and cross-referencing with real-time threat intelligence sources. Once the analysis is complete, the page will automatically update with enriched vulnerability data and actionable insights.

No IOCs found for this CVE

No exploits found for this CVE

SOCRadar Logo

Enhance Your CVE Management with SOCRadar Vulnerability Intelligence

Get comprehensive CVE details, real-time notifications, and proactive threat management all in one platform.

CREATE FREE ACCOUNT
CVE Details
Access comprehensive CVE information instantly
Real-time Tracking
Subscribe to CVEs and get instant updates
Exploit Analysis
Monitor related APT groups and threats
IOC Tracking
Analyze and track CVE-related IOCs

No news found for this CVE

No tweets found for this CVE

Configuration 1
TypeVendorProduct
AppDonglightbookstore
ReferenceLink
134C704F-9B21-4F2E-91B3-4A467353BCC0https://github.com/donglight/bookstore/issues/11
134C704F-9B21-4F2E-91B3-4A467353BCC0https://github.com/donglight/bookstore/issues/11%23issue-2760929273
[email protected]https://github.com/donglight/bookstore/issues/11
[email protected]https://github.com/donglight/bookstore/issues/11%23issue-2760929273
[email protected]https://github.com/donglight/bookstore/issues/11
[email protected]https://github.com/donglight/bookstore/issues/11#issue-2760929273
[email protected]https://vuldb.com/?ctiid.290787
[email protected]https://vuldb.com/?id.290787
[email protected]https://vuldb.com/?submit.469689
134C704F-9B21-4F2E-91B3-4A467353BCC0https://github.com/donglight/bookstore/issues/11
134C704F-9B21-4F2E-91B3-4A467353BCC0https://github.com/donglight/bookstore/issues/11#issue-2760929273
[email protected]https://github.com/donglight/bookstore/issues/11
[email protected]https://github.com/donglight/bookstore/issues/11#issue-2760929273
[email protected]https://vuldb.com/?ctiid.290787
[email protected]https://vuldb.com/?id.290787
[email protected]https://vuldb.com/?submit.469689
SUBMIT #469689 | DONGLIGHT BOOKSTORE 1.0 SSRFhttps://vuldb.com/?submit.469689
VDB-290787 | CTI INDICATORS (IOB, IOC, IOA)https://vuldb.com/?ctiid.290787
VDB-290787 | DONGLIGHT BOOKSTORE电商书城系统说明 HTTPUTIL.JAVA GETHTML SERVER-SIDE REQUEST FORGERYhttps://vuldb.com/?id.290787
GITHUBhttps://vuldb.com/?id.290787
134C704F-9B21-4F2E-91B3-4A467353BCC0https://github.com/donglight/bookstore/issues/11
134C704F-9B21-4F2E-91B3-4A467353BCC0https://github.com/donglight/bookstore/issues/11#issue-2760929273
[email protected]https://github.com/donglight/bookstore/issues/11
[email protected]https://github.com/donglight/bookstore/issues/11#issue-2760929273
[email protected]https://vuldb.com/?ctiid.290787
[email protected]https://vuldb.com/?id.290787
[email protected]https://vuldb.com/?submit.469689
134C704F-9B21-4F2E-91B3-4A467353BCC0https://github.com/donglight/bookstore/issues/11
[email protected]https://github.com/donglight/bookstore/issues/11
[email protected]https://github.com/donglight/bookstore/issues/11%23issue-2760929273
[email protected]https://vuldb.com/?id.290787
[email protected]https://vuldb.com/?submit.469689
CWE IDCWE NameDescription
CWE-918Server-Side Request Forgery (SSRF)The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

CVE Radar

Real-time CVE Intelligence & Vulnerability Management Platform

CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.