PT-2025-32481 · Unknown · Xujeff Tianti 天梯

N1N3B9S

·

Published

2025-08-10

·

Updated

2025-08-10

·

CVE-2025-8807

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: xujeff tianti 天梯 versions prior to 2.3
Description: A critical issue exists in xujeff tianti 天梯, potentially leading to missing authorization. The vulnerability affects unknown code within the /tianti-module-admin/user/ajax/save API endpoint and can be exploited remotely. The exploit has been publicly disclosed. The vendor was notified but did not respond.
Recommendations: Update to a version prior to 2.3 to address this issue.

Exploit

Fix

Incorrect Authorization

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2025-8807

Affected Products

Xujeff Tianti 天梯