PT-2025-40848 · Unknown · Zhuimengshaonian Wisdom-Education

Xkalami

·

Published

2025-10-06

·

Updated

2025-10-06

·

CVE-2025-11320

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions zhuimengshaonian wisdom-education versions prior to 1.0.5
Description A security issue exists in zhuimengshaonian wisdom-education. The uploadFile function within the file src/main/java/com/education/core/controller/UploadController.java is susceptible to unrestricted file upload. Manipulation of the File argument can lead to remote exploitation. The exploit has been publicly disclosed.
Recommendations Update zhuimengshaonian wisdom-education to version 1.0.5 or later. As a temporary workaround, restrict access to the uploadFile function until a patch is available.

Exploit

Fix

Improper Access Control

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2025-11320

Affected Products

Zhuimengshaonian Wisdom-Education