PT-2025-15353 · Unknown · Mymagicpower Aias
Tr0E
·
Published
2025-04-08
·
Updated
2025-04-08
·
CVE-2025-3410
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
mymagicpower AIAS 20250308
Description:
A critical issue was found in the code of the file training platform/train-platform/src/main/java/top/aias/training/controller/LocalStorageController.java, affecting the
File argument. This allows for unrestricted upload. The attack can be initiated remotely. An exploit has been publicly disclosed and may be used. The vendor was contacted about this issue but did not respond.Recommendations:
For mymagicpower AIAS 20250308, as a temporary workaround, consider restricting access to the
LocalStorageController.java file until a patch is available. Avoid using the File argument in the affected controller to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
Improper Access Control
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Mymagicpower Aias