CVE-2025-2323

A vulnerability was found in 274056675 springboot-openai-chatgpt e84f6f5. It has been declared as problematic. This vulnerability affects the function updateQuestionCou of the file /api/mjkj-chat/chat/mng/update/questionCou of the component Number of Question Handler. The manipulation leads to enforcement of behavioral workflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available. The vendor was contacted early about this disclosure but did not respond in any way.
References
Link Resource
https://vuldb.com/?ctiid.299752 Permissions Required VDB Entry
https://vuldb.com/?id.299752 Third Party Advisory VDB Entry
https://vuldb.com/?submit.505695 Third Party Advisory VDB Entry
https://www.cnblogs.com/aibot/p/18732309 Exploit Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:274056675:springboot-openai-chatgpt:2024-12-29:*:*:*:*:*:*:*

History

24 Oct 2025, 18:21

Type Values Removed Values Added
First Time 274056675
274056675 springboot-openai-chatgpt
Summary
  • (es) Se encontró una vulnerabilidad en 274056675 springboot-openai-chatgpt e84f6f5. Se ha declarado problemática. Esta vulnerabilidad afecta a la función updateQuestionCou del archivo /api/mjkj-chat/chat/mng/update/questionCou del componente Number of Question Handler. La manipulación conlleva la aplicación de un flujo de trabajo basado en comportamientos. El ataque puede iniciarse remotamente. Se ha hecho público el exploit y puede que sea utilizado. Este producto utiliza una versión continua para proporcionar una entrega continua. Por lo tanto, no se dispone de detalles de las versiones afectadas ni de las actualizadas. Se contactó al proveedor con antelación sobre esta divulgación, pero no respondió de ninguna manera.
CPE cpe:2.3:a:274056675:springboot-openai-chatgpt:2024-12-29:*:*:*:*:*:*:*
References () https://vuldb.com/?ctiid.299752 - () https://vuldb.com/?ctiid.299752 - Permissions Required, VDB Entry
References () https://vuldb.com/?id.299752 - () https://vuldb.com/?id.299752 - Third Party Advisory, VDB Entry
References () https://vuldb.com/?submit.505695 - () https://vuldb.com/?submit.505695 - Third Party Advisory, VDB Entry
References () https://www.cnblogs.com/aibot/p/18732309 - () https://www.cnblogs.com/aibot/p/18732309 - Exploit, Third Party Advisory

15 Mar 2025, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-15 17:15

Updated : 2025-10-24 18:21


NVD link : CVE-2025-2323

Mitre link : CVE-2025-2323

CVE.ORG link : CVE-2025-2323


JSON object : View

Products Affected

274056675

  • springboot-openai-chatgpt
CWE
CWE-840

Business Logic Errors

CWE-841

Improper Enforcement of Behavioral Workflow