CNNVD-202512-4883 Information

CNNVD ID

CNNVD-202512-4883

CVE-2025-15134

  • CNNVD Published: 2025-12-28

Description (Chinese)

MOOC是yourmaileyes个人开发者的一个在线视频教育网站。 MOOC 1.17及之前版本存在代码注入漏洞,该漏洞源于文件mooc/controller/MainController.java中参数review的错误操作,可能导致跨站脚本。

Description (English)

MOOC is an online video education site for yourmaileyes personal developers. MOOC 1.17 and previous versions have code-injecting holes, which stem from the error of review, the parameter in document mooc/controller/MainController.java, which may result in a cross-site script.

Hazard Level

Critical

Vulnerability Type

代码注入

Affected Vendor

个人开发者

Published

2025-12-28

Last Modified

2026-02-24

References

https://github.com/yourmaileyes/MOOC/issues/12#issue-3722197285 https://vuldb.com/?submit.713955 https://vuldb.com/?ctiid.338512 https://vuldb.com/?id.338512 https://access.redhat.com/security/cve/cve-2025-15134

Share on: