PT-2026-25830 · Unknown · Taoofagi Easegen-Admin

Vuldb

+1

·

Publicado

2026-03-16

·

Atualizado

2026-03-17

·

CVE-2026-4285

CVSS v2.0

3.3

Baixa

VetorAV:N/AC:L/Au:M/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions taoofagi easegen-admin versions prior to 8f87936ac774065b92fb20aab55b274a6ea76433
Description A path traversal issue exists in the recognizeMarkdown function within the file yudao-module-digitalcourse/yudao-module-digitalcourse-biz/src/main/java/cn/iocoder/yudao/module/digitalcourse/util/Pdf2MdUtil.java. Manipulation of the fileUrl argument can lead to unauthorized access. The attack can be launched remotely, and an exploit is publicly available. The software utilizes a rolling release model, meaning specific version details for fixes are not available. The vendor was notified of the issue but did not respond.
Recommendations Versions prior to 8f87936ac774065b92fb20aab55b274a6ea76433 should be updated. As a temporary workaround, consider restricting access to the recognizeMarkdown function until a suitable update is available.

Exploit

Correção

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-4285

Produtos afetados

Taoofagi Easegen-Admin