CVE-2024-8707: Yunknet Yunke Online School System

Medium severity, CVSS 4.3. EPSS: 0.5% chance of exploitation in the next 30 days.

A vulnerability was found in 云课网络科技有限公司 Yunke Online School System up to 3.0.6. It has been declared as problematic. This vulnerability affects the function downfile of the file application/admin/controller/Appadmin.php. The manipulation of the argument url leads to path traversal. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

Affected products

  • Yunknet Yunke Online School System: version 3.0.0 only; version 3.0.1 only; version 3.0.2 only; version 3.0.3 only; version 3.0.4 only; version 3.0.5 only; …
  • 云课网络科技有限公司 Yunke Online School System: version 3.0.0 only; version 3.0.1 only; version 3.0.2 only; version 3.0.3 only; version 3.0.4 only; version 3.0.5 only; …

Published 2024-09-12. Last modified 2026-06-17.