VulnerabilityAnalyzed
CVE-2025-1947
A vulnerability classified as critical has been found in hzmanyun Education and Training System 2.1.3.
MEDIUM 5.3EPSS 5.15%
Does this matter?
Lower severity and a low EPSS score (5.15%). Track it; it rarely justifies an emergency change on its own.
Description
A vulnerability classified as critical has been found in hzmanyun Education and Training System 2.1.3. This affects the function scorm of the file UploadImageController.java. The manipulation of the argument param leads to command injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
- CVSS 4.0
- 5.3 MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
- EPSS
- 5.15% probability · 92th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-74, CWE-77
- Affected
- hzmanyun/education and training system
- Source
- cna@vuldb.com
References
- https://github.com/heiheixz/report/blob/main/nxb_2.mdExploit, Mitigation, Third Party Advisory
- https://vuldb.com/?ctiid.298521Permissions Required, VDB Entry
- https://vuldb.com/?id.298521Third Party Advisory, VDB Entry
- https://vuldb.com/?submit.506659Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.