The tumbnail API of Tronclass from WisdomGarden lacks proper access control, allowing unauthenticated remote attackers to obtain certain specific files by modifying the URL.
Affected Software
Name |
Vendor |
Start Version |
End Version |
Tronclass |
Wisdomgarden |
* |
1.69.61976 (excluding) |
References