CNNVD-202510-856 Information

CNNVD ID

CNNVD-202510-856

CVE-2025-11320

  • CNNVD Published: 2025-10-06

Description (Chinese)

wisdom-education是zhuimengshaonian个人开发者的一款云智能教育平台。 wisdom-education 1.0.4及之前版本存在代码问题漏洞,该漏洞源于对文件src/main/java/com/education/core/controller/UploadController.java中参数File的错误操作,可能导致任意文件上传。

Description (English)

Wisdom-education is a cloud-intellectual educational platform for zhuimenengshaonian personal developers. Wisdom-education 1.0.4 and previous versions had a code problem loophole, which stemmed from an error in the File parameter in document src/main/java/com/education/core/controller/UploadController.java, which could lead to any upload.

Hazard Level

High

Vulnerability Type

代码问题

Affected Vendor

个人开发者

Published

2025-10-06

Last Modified

2026-02-24

References

https://github.com/xkalami-Tta0/CVE/blob/main/wisdom-education/%E5%89%8D%E5%8F%B0%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0.md https://github.com/xkalami-Tta0/CVE/blob/main/wisdom-education/%E5%89%8D%E5%8F%B0%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0.md#vulnerability-reproduction https://vuldb.com/?ctiid.327201 https://vuldb.com/?id.327201 https://vuldb.com/?submit.664392

Share on: