CNNVD-202512-4883 Information
Dec 28, 2025
cve
CNNVD ID
CNNVD-202512-4883
Related CVE
- CNNVD Published: 2025-12-28
Description (Chinese)
MOOC是yourmaileyes个人开发者的一个在线视频教育网站。 MOOC 1.17及之前版本存在代码注入漏洞,该漏洞源于文件mooc/controller/MainController.java中参数review的错误操作,可能导致跨站脚本。
Description (English)
MOOC is an online video education site for yourmaileyes personal developers. MOOC 1.17 and previous versions have code-injecting holes, which stem from the error of review, the parameter in document mooc/controller/MainController.java, which may result in a cross-site script.
Hazard Level
Critical
Vulnerability Type
代码注入
Affected Vendor
个人开发者
Published
2025-12-28
Last Modified
2026-02-24
References
https://github.com/yourmaileyes/MOOC/issues/12#issue-3722197285 https://vuldb.com/?submit.713955 https://vuldb.com/?ctiid.338512 https://vuldb.com/?id.338512 https://access.redhat.com/security/cve/cve-2025-15134
Share on: