Metrics
Affected Vendors & Products
Mon, 06 Oct 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 06 Oct 2025 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Zhuimengshaonian
Zhuimengshaonian wisdom-education |
|
| Vendors & Products |
Zhuimengshaonian
Zhuimengshaonian wisdom-education |
Mon, 06 Oct 2025 04:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A security vulnerability has been detected in zhuimengshaonian wisdom-education up to 1.0.4. Impacted is the function uploadFile of the file src/main/java/com/education/core/controller/UploadController.java. Such manipulation of the argument File leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used. | |
| Title | zhuimengshaonian wisdom-education UploadController.java uploadFile unrestricted upload | |
| Weaknesses | CWE-284 CWE-434 |
|
| References |
|
|
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published: 2025-10-06T04:32:06.583Z
Updated: 2025-10-06T19:17:16.405Z
Reserved: 2025-10-05T06:35:54.975Z
Link: CVE-2025-11320
Updated: 2025-10-06T19:17:04.776Z
Status : Awaiting Analysis
Published: 2025-10-06T05:15:33.523
Modified: 2025-10-06T14:56:21.733
Link: CVE-2025-11320
No data.