CVE-2024-6738: Wisdomgarden Tronclass

Medium severity, CVSS 5.3. EPSS: 0.5% chance of exploitation in the next 30 days.

The tumbnail API of Tronclass from WisdomGarden lacks proper access control, allowing unauthenticated remote attackers to obtain certain specific files by modifying the URL.

Affected products

  • Wisdomgarden Tronclass: before 1.69.61976 (fixed in 1.69.61976)

Published 2024-07-15. Last modified 2026-06-17.