PT-2025-16928 · Unknown · Wisdom Master Pro

Kuang Ming Chang

·

Published

2025-04-17

·

Updated

2025-04-18

·

CVE-2025-31340

CVSS v4.0

9.9

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:H
Name of the Vulnerable Software and Affected Versions Wisdom Master Pro versions 5.0 through 5.2
Description A vulnerability in the retrieve course Information function of Wisdom Master Pro allows remote attackers to perform arbitrary system commands by running a malicious file due to improper control of filename for include/require statement in PHP program. This issue enables remote code execution with no authentication.
Recommendations For Wisdom Master Pro versions 5.0 through 5.2, consider disabling the retrieve course Information function until a patch is available to prevent exploitation. Restrict access to the vulnerable PHP program to minimize the risk of arbitrary system command execution. Avoid using the vulnerable include/require statement in the affected function until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Weakness Enumeration

Related Identifiers

CVE-2025-31340

Affected Products

Wisdom Master Pro