A vulnerability has been found in xujeff tianti 天梯 up to 2.3. The impacted element is the function ajaxUploadFile of the file src/main/java/com/jeff/tianti/controller/UploadController.java. The manipulation of the argument upfile leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
                
            References
                    | Link | Resource | 
|---|---|
| https://github.com/xujeff/tianti/issues/43 | Exploit Issue Tracking | 
| https://github.com/xujeff/tianti/issues/43#issue-3287851827 | Exploit | 
| https://vuldb.com/?ctiid.322110 | Permissions Required VDB Entry | 
| https://vuldb.com/?id.322110 | Third Party Advisory VDB Entry | 
| https://vuldb.com/?submit.641122 | Third Party Advisory VDB Entry | 
| https://github.com/xujeff/tianti/issues/43 | Exploit Issue Tracking | 
| https://github.com/xujeff/tianti/issues/43#issue-3287851827 | Exploit | 
Configurations
                    History
                    04 Sep 2025, 16:53
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time | Tianti Project tianti Tianti Project | |
| CPE | cpe:2.3:a:tianti_project:tianti:*:*:*:*:*:*:*:* | |
| References | () https://github.com/xujeff/tianti/issues/43 - Exploit, Issue Tracking | |
| References | () https://github.com/xujeff/tianti/issues/43#issue-3287851827 - Exploit | |
| References | () https://vuldb.com/?ctiid.322110 - Permissions Required, VDB Entry | |
| References | () https://vuldb.com/?id.322110 - Third Party Advisory, VDB Entry | |
| References | () https://vuldb.com/?submit.641122 - Third Party Advisory, VDB Entry | 
02 Sep 2025, 15:15
| Type | Values Removed | Values Added | 
|---|---|---|
| References | () https://github.com/xujeff/tianti/issues/43 - | |
| References | () https://github.com/xujeff/tianti/issues/43#issue-3287851827 - | 
01 Sep 2025, 21:15
| Type | Values Removed | Values Added | 
|---|---|---|
| New CVE | 
Information
                Published : 2025-09-01 21:15
Updated : 2025-09-04 16:53
NVD link : CVE-2025-9795
Mitre link : CVE-2025-9795
CVE.ORG link : CVE-2025-9795
JSON object : View
Products Affected
                tianti_project
- tianti
