PT-2025-29343 · Unknown · Joeybling Springboot Mybatisplus
Bi8Bu
·
Published
2025-07-12
·
Updated
2025-07-12
·
CVE-2025-7487
CVSS v2.0
6.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
JoeyBling SpringBoot MyBatisPlus versions prior to a6a825513bd688f717dbae3a196bc9c9622fea26
Description:
A critical vulnerability exists in the
SysFileController function located at /file/upload within JoeyBling SpringBoot MyBatisPlus. Manipulation of the portraitFile argument allows for unrestricted file upload, enabling remote exploitation. The exploit has been publicly disclosed.Recommendations:
Update JoeyBling SpringBoot MyBatisPlus to a version beyond a6a825513bd688f717dbae3a196bc9c9622fea26.
As a temporary workaround, restrict access to the
/file/upload endpoint.
Avoid using the portraitFile parameter in the /file/upload endpoint until the issue is resolved.Exploit
Fix
Improper Access Control
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Joeybling Springboot Mybatisplus