A vulnerability has been found in xujeff tianti 天梯 up to 2.3. The impacted element is the function ajaxUploadFile of the file src/main/java/com/jeff/tianti/controller/UploadController.java. The manipulation of the argument upfile leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
References
Link | Resource |
---|---|
https://github.com/xujeff/tianti/issues/43 | Exploit Issue Tracking |
https://github.com/xujeff/tianti/issues/43#issue-3287851827 | Exploit |
https://vuldb.com/?ctiid.322110 | Permissions Required VDB Entry |
https://vuldb.com/?id.322110 | Third Party Advisory VDB Entry |
https://vuldb.com/?submit.641122 | Third Party Advisory VDB Entry |
https://github.com/xujeff/tianti/issues/43 | Exploit Issue Tracking |
https://github.com/xujeff/tianti/issues/43#issue-3287851827 | Exploit |
Configurations
History
04 Sep 2025, 16:53
Type | Values Removed | Values Added |
---|---|---|
First Time |
Tianti Project tianti
Tianti Project |
|
CPE | cpe:2.3:a:tianti_project:tianti:*:*:*:*:*:*:*:* | |
References | () https://github.com/xujeff/tianti/issues/43 - Exploit, Issue Tracking | |
References | () https://github.com/xujeff/tianti/issues/43#issue-3287851827 - Exploit | |
References | () https://vuldb.com/?ctiid.322110 - Permissions Required, VDB Entry | |
References | () https://vuldb.com/?id.322110 - Third Party Advisory, VDB Entry | |
References | () https://vuldb.com/?submit.641122 - Third Party Advisory, VDB Entry |
02 Sep 2025, 15:15
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/xujeff/tianti/issues/43 - | |
References | () https://github.com/xujeff/tianti/issues/43#issue-3287851827 - |
01 Sep 2025, 21:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-09-01 21:15
Updated : 2025-09-04 16:53
NVD link : CVE-2025-9795
Mitre link : CVE-2025-9795
CVE.ORG link : CVE-2025-9795
JSON object : View
Products Affected
tianti_project
- tianti