Cyber Posture

CVE-2024-13110

MediumPublic PoC

Published: 02 January 2025

Published
02 January 2025
Modified
25 August 2025
KEV Added
Patch
CVSS Score 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
EPSS Score 0.0020 41.5th percentile
Risk Priority 9 60% EPSS · 20% KEV · 20% CVSS

Description

A vulnerability classified as problematic has been found in Beijing Yunfan Internet Technology Yunfan Learning Examination System 1.9.2. Affected is an unknown function of the file src/main/java/com/yf/exam/modules/paper/controller/PaperController.java, of the component Exam Answer Handler. The manipulation leads to information disclosure. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

Security Summary

CVE-2024-13110 is a problematic information disclosure vulnerability affecting Beijing Yunfan Internet Technology's Yunfan Learning Examination System version 1.9.2. The issue resides in an unknown function within the file src/main/java/com/yf/exam/modules/paper/controller/PaperController.java, part of the Exam Answer Handler component. Manipulation of this function results in the exposure of sensitive information, with the vulnerability carrying a CVSS v3.1 base score of 4.3 (AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N) and mapped to CWEs-200 (Exposure of Sensitive Information to an Unauthorized Actor) and CWE-284 (Improper Access Control).

The vulnerability can be exploited remotely by an authenticated attacker with low privileges (PR:L), requiring no user interaction and low attack complexity. Successful exploitation allows the attacker to obtain limited confidential information (C:L), such as potentially sensitive data handled by the Exam Answer Handler, without impacting integrity or availability.

Advisories published on VulDB (ctiid.289926, id.289926) and GitHub (qiutiandefeng/yfexam-exam issues/5 and #5#issue-2754675223) detail the vulnerability, confirming that a public exploit has been disclosed and may be actively used. No specific patches or mitigations are outlined in the available references; security practitioners should review the GitHub issue for potential workarounds or updates from the vendor.

The exploit's public disclosure increases the risk of immediate exploitation in unpatched environments running the affected system.

Details

CWE(s)
CWE-200CWE-284NVD-CWE-noinfo

Affected Products

kaoshifeng
yunfan learning examination system
1.9.2

References