Quequnlong · Shiyi-Blog · CVE-2025-12305
**Name of the Vulnerable Software and Affected Versions**
quequnlong shiyi-blog versions up to 1.2.1
**Description**
A flaw exists in the Job Handler component of quequnlong shiyi-blog. The issue involves deserialization within an unknown function of the file `src/main/java/com/mojian/controller/SysJobController.java`. This can be exploited remotely. The exploit is publicly available.
**Recommendations**
Versions prior to 1.2.1 should be updated. As a temporary workaround, consider restricting access to the `SysJobController.java` file to minimize the risk of exploitation.