CVE-2025-12268
A vulnerability has been found in LearnHouse up to 98dfad76aad70711a8113f6c1fdabfccf10509ca.
Does this matter?
Lower severity and a low EPSS score (0.38%). Track it; it rarely justifies an emergency change on its own.
Description
A vulnerability has been found in LearnHouse up to 98dfad76aad70711a8113f6c1fdabfccf10509ca. Impacted is an unknown function of the file /api/v1/courses/ of the component Course Thumbnail Handler. The manipulation of the argument thumbnail leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available. The vendor was contacted early about this disclosure but did not respond in any way.
- CVSS 4.0
- 2.1 LOWCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
- EPSS
- 0.38% probability · 32th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-284, CWE-434
- Affected
- learnhouse/learnhouse
- Source
- cna@vuldb.com
References
- https://gist.github.com/KhanMarshaI/ef07d20eb1cbe30c71722fbded7cc056Exploit, Third Party Advisory
- https://vuldb.com/?ctiid.329940Permissions Required, VDB Entry
- https://vuldb.com/?id.329940Third Party Advisory, VDB Entry
- https://vuldb.com/?submit.674145Third Party Advisory, VDB Entry
- https://gist.github.com/KhanMarshaI/ef07d20eb1cbe30c71722fbded7cc056Exploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.