CVE-2025-11321

A vulnerability was detected in zhuimengshaonian wisdom-education up to 1.0.4. The affected element is an unknown function of the file src/main/java/com/education/api/controller/student/WrongBookController.java. Performing manipulation of the argument subjectId results in authorization bypass. The attack can be initiated remotely. The exploit is now public and may be used.
Configurations

No configuration.

History

06 Oct 2025, 05:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-10-06 05:15

Updated : 2025-10-06 14:56


NVD link : CVE-2025-11321

Mitre link : CVE-2025-11321

CVE.ORG link : CVE-2025-11321


JSON object : View

Products Affected

No product.

CWE
CWE-285

Improper Authorization

CWE-639

Authorization Bypass Through User-Controlled Key