A vulnerability has been found in xujeff tianti 天梯 up to 2.3. The impacted element is the function ajaxUploadFile of the file src/main/java/com/jeff/tianti/controller/UploadController.java. The manipulation of the argument upfile leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
References
Link | Resource |
---|---|
https://github.com/xujeff/tianti/issues/43 | Exploit Issue Tracking |
https://github.com/xujeff/tianti/issues/43#issue-3287851827 | Exploit |
https://vuldb.com/?ctiid.322110 | Permissions Required VDB Entry |
https://vuldb.com/?id.322110 | Third Party Advisory VDB Entry |
https://vuldb.com/?submit.641122 | Third Party Advisory VDB Entry |
https://github.com/xujeff/tianti/issues/43 | Exploit Issue Tracking |
https://github.com/xujeff/tianti/issues/43#issue-3287851827 | Exploit |
Configurations
History
04 Sep 2025, 16:53
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/xujeff/tianti/issues/43 - Exploit, Issue Tracking | |
References | () https://github.com/xujeff/tianti/issues/43#issue-3287851827 - Exploit | |
References | () https://vuldb.com/?ctiid.322110 - Permissions Required, VDB Entry | |
References | () https://vuldb.com/?id.322110 - Third Party Advisory, VDB Entry | |
References | () https://vuldb.com/?submit.641122 - Third Party Advisory, VDB Entry | |
CPE | cpe:2.3:a:tianti_project:tianti:*:*:*:*:*:*:*:* | |
First Time |
Tianti Project
Tianti Project tianti |
02 Sep 2025, 15:15
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/xujeff/tianti/issues/43 - | |
References | () https://github.com/xujeff/tianti/issues/43#issue-3287851827 - |
01 Sep 2025, 21:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-09-01 21:15
Updated : 2025-09-04 16:53
NVD link : CVE-2025-9795
Mitre link : CVE-2025-9795
CVE.ORG link : CVE-2025-9795
JSON object : View
Products Affected
tianti_project
- tianti