Severity
5.1MEDIUM
EPSS
0.3%
top 42.59%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 14

Description

A vulnerability classified as critical was found in huanfenz/code-projects StudentManager 1.0. This vulnerability affects unknown code of the file /upload/uploadArticle.do of the component Announcement Management Section. The manipulation of the argument File leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N

Affected Packages3 packages

🔴Vulnerability Details

2
GHSA
GHSA-4r8p-gh25-7c48: A vulnerability classified as critical was found in huanfenz/code-projects StudentManager 12025-04-14
CVEList
huanfenz/code-projects StudentManager Announcement Management Section uploadArticle.do unrestricted upload2025-04-14

📋Vendor Advisories

1
Microsoft
A flaw was found in tpm2-tools in versions before 5.1.1 and before 4.3.2. tpm2_import used a fixed AES key for the inner wrapper potentially allowing a MITM attacker to unwrap the inner portion and re2021-06-08
CVE-2025-3565 (MEDIUM CVSS 5.1) | A vulnerability classified as criti | cvebase.io