CVE-2025-11320

A security vulnerability has been detected in zhuimengshaonian wisdom-education up to 1.0.4. Impacted is the function uploadFile of the file src/main/java/com/education/core/controller/UploadController.java. Such manipulation of the argument File leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used.
Configurations

No configuration.

History

06 Oct 2025, 05:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-10-06 05:15

Updated : 2025-10-06 14:56


NVD link : CVE-2025-11320

Mitre link : CVE-2025-11320

CVE.ORG link : CVE-2025-11320


JSON object : View

Products Affected

No product.

CWE
CWE-284

Improper Access Control

CWE-434

Unrestricted Upload of File with Dangerous Type