CNNVD-202601-3807 Information
CNNVD ID
CNNVD-202601-3807
Related CVE
- CNNVD Published: 2026-01-22
Description (Chinese)
EduSoho是EduSoho开源的一个网校系统。 EduSoho 22.4.7之前版本存在路径遍历漏洞,该漏洞源于classroom-course-statistics导出功能中对fileNames参数处理不当,可能导致任意文件读取。
Description (English)
EduSoho is an online school system that is open to EduSoho. EduSoho 22.4.7 has a loophole in the path from the inappropriate handling of fileNames parameters in the cassroom-course-statistics export function, which may lead to any reading of files.
Hazard Level
High
Vulnerability Type
路径遍历
Affected Vendor
EduSoho
Published
2026-01-22
Last Modified
2026-02-24
References
https://blog.csdn.net/qq_41904294/article/details/135007351 https://github.com/zeroChen00/exp-poc/blob/main/EduSoho%E6%95%99%E5%9F%B9%E7%B3%BB%E7%BB%9Fclassropm-course-statistics%E5%AD%98%E5%9C%A8%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96%E6%BC%8F%E6%B4%9E.md https://github.com/edusoho/edusoho/releases/tag/v22.4.7 https://www.edusoho.com/ https://cn-sec.com/archives/2451582.html https://www.cnvd.org.cn/flaw/show/CNVD-2023-03903 https://www.vulncheck.com/advisories/edusoho-arbitrary-file-read-via-classroom-course-statistics https://github.com/gobysec/GobyVuls/blob/master/CNVD-2023-03903.md https://access.redhat.com/security/cve/cve-2023-7335
Patch
https://github.com/edusoho/edusoho/releases
Share on: