A vulnerability has been found in xujeff tianti 天梯 up to 2.3. The impacted element is the function ajaxUploadFile of the file src/main/java/com/jeff/tianti/controller/UploadController.java. The manipulation of the argument upfile leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Metrics
Affected Vendors & Products
References
History
Mon, 01 Sep 2025 21:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A vulnerability has been found in xujeff tianti 天梯 up to 2.3. The impacted element is the function ajaxUploadFile of the file src/main/java/com/jeff/tianti/controller/UploadController.java. The manipulation of the argument upfile leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. | |
Title | xujeff tianti 天梯 UploadController.java ajaxUploadFile unrestricted upload | |
Weaknesses | CWE-284 CWE-434 |
|
References |
| |
Metrics |
cvssV2_0
|

Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2025-09-01T21:02:06.245Z
Reserved: 2025-09-01T11:38:37.454Z
Link: CVE-2025-9795

No data.

Status : Received
Published: 2025-09-01T21:15:29.607
Modified: 2025-09-01T21:15:29.607
Link: CVE-2025-9795

No data.

No data.