PT-2025-29343 · Unknown · Joeybling Springboot Mybatisplus

Bi8Bu

·

Published

2025-07-12

·

Updated

2025-07-12

·

CVE-2025-7487

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: JoeyBling SpringBoot MyBatisPlus versions prior to a6a825513bd688f717dbae3a196bc9c9622fea26
Description: A critical vulnerability exists in the SysFileController function located at /file/upload within JoeyBling SpringBoot MyBatisPlus. Manipulation of the portraitFile argument allows for unrestricted file upload, enabling remote exploitation. The exploit has been publicly disclosed.
Recommendations: Update JoeyBling SpringBoot MyBatisPlus to a version beyond a6a825513bd688f717dbae3a196bc9c9622fea26. As a temporary workaround, restrict access to the /file/upload endpoint. Avoid using the portraitFile parameter in the /file/upload endpoint until the issue is resolved.

Exploit

Fix

Improper Access Control

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2025-7487

Affected Products

Joeybling Springboot Mybatisplus