A security vulnerability has been detected in zhuimengshaonian wisdom-education up to 1.0.4. This vulnerability affects the function selectStudentExamInfoList of the file src/main/java/com/education/api/controller/student/ExamInfoController.java. Such manipulation of the argument subjectId leads to improper authorization. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used.
Metrics
Affected Vendors & Products
References
History
Mon, 29 Sep 2025 09:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Zhuimengshaonian
Zhuimengshaonian wisdom-education |
|
Vendors & Products |
Zhuimengshaonian
Zhuimengshaonian wisdom-education |
Sat, 27 Sep 2025 21:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A security vulnerability has been detected in zhuimengshaonian wisdom-education up to 1.0.4. This vulnerability affects the function selectStudentExamInfoList of the file src/main/java/com/education/api/controller/student/ExamInfoController.java. Such manipulation of the argument subjectId leads to improper authorization. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used. | |
Title | zhuimengshaonian wisdom-education ExamInfoController.java selectStudentExamInfoList improper authorization | |
Weaknesses | CWE-266 CWE-285 |
|
References |
|
|
Metrics |
cvssV2_0
|

Status: PUBLISHED
Assigner: VulDB
Published: 2025-09-27T21:32:06.699Z
Updated: 2025-09-27T21:32:06.699Z
Reserved: 2025-09-26T13:11:04.929Z
Link: CVE-2025-11080

No data.

Status : Received
Published: 2025-09-27T22:15:31.430
Modified: 2025-09-27T22:15:31.430
Link: CVE-2025-11080

No data.