go to Content
:::

TWCERT/CC Taiwan Computer Emergency Response Team/Coordination Center

:::
Date:
Font-stze:

WisdomGarden|Tronclass - Insecure Direct Object Reference

TVN ID TVN-202509007
CVE ID CVE-2025-10719
CVSS 4.3 (Medium)
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Affected Products Tronclass version 1.74 and earlier
Description Tronclass developed by WisdomGarden has an Insecure Direct object Reference vulnerability, allowing remote attackers with regular privilege to modify a specific parameter to access other users' files.
Solution Update to version 1.77 and later
Credit HSIN-CHE, WU
Public Date 2025-09-19
Top