CNNVD-202509-4235 Information

CNNVD ID

CNNVD-202509-4235

CVE-2025-11078

  • CNNVD Published: 2025-09-27

Description (Chinese)

itsourcecode Open Source Job Portal是itsourcecode开源的一个企业门户站点。 itsourcecode Open Source Job Portal 1.0版本存在代码问题漏洞,该漏洞源于对文件/admin/user/controller.php中参数photo的错误操作,可能导致任意文件上传。

Description (English)

Its sourcecode Open Source Job Portal is an enterprise portal to open source. Its sourcecodecode Open Source Job Portal 1.0 has a code problem loophole, which stems from an error in the photo parameter in file/admin/user/controller.php and may lead to any upload.

Hazard Level

High

Vulnerability Type

代码问题

Affected Vendor

itsourcecode

Published

2025-09-27

Last Modified

2026-02-24

References

https://vuldb.com/?submit.660919 https://github.com/fengbenjianmo/CVE/issues/1 https://vuldb.com/?id.326118 https://vuldb.com/?ctiid.326118 https://itsourcecode.com/ https://access.redhat.com/security/cve/cve-2025-11078

Share on: