Metrics
Affected Vendors & Products
Mon, 29 Sep 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 29 Sep 2025 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Zhuimengshaonian
Zhuimengshaonian wisdom-education |
|
| Vendors & Products |
Zhuimengshaonian
Zhuimengshaonian wisdom-education |
Sat, 27 Sep 2025 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A security vulnerability has been detected in zhuimengshaonian wisdom-education up to 1.0.4. This vulnerability affects the function selectStudentExamInfoList of the file src/main/java/com/education/api/controller/student/ExamInfoController.java. Such manipulation of the argument subjectId leads to improper authorization. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used. | |
| Title | zhuimengshaonian wisdom-education ExamInfoController.java selectStudentExamInfoList improper authorization | |
| Weaknesses | CWE-266 CWE-285 |
|
| References |
|
|
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published: 2025-09-27T21:32:06.699Z
Updated: 2025-09-29T19:36:16.945Z
Reserved: 2025-09-26T13:11:04.929Z
Link: CVE-2025-11080
Updated: 2025-09-29T19:36:12.498Z
Status : Awaiting Analysis
Published: 2025-09-27T22:15:31.430
Modified: 2025-09-29T19:34:10.030
Link: CVE-2025-11080
No data.