A vulnerability has been found in xujeff tianti 天梯 up to 2.3. The impacted element is the function ajaxUploadFile of the file src/main/java/com/jeff/tianti/controller/UploadController.java. The manipulation of the argument upfile leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
References
| Link | Resource |
|---|---|
| https://github.com/xujeff/tianti/issues/43 | Exploit Issue Tracking |
| https://github.com/xujeff/tianti/issues/43#issue-3287851827 | Exploit |
| https://vuldb.com/?ctiid.322110 | Permissions Required VDB Entry |
| https://vuldb.com/?id.322110 | Third Party Advisory VDB Entry |
| https://vuldb.com/?submit.641122 | Third Party Advisory VDB Entry |
| https://github.com/xujeff/tianti/issues/43 | Exploit Issue Tracking |
| https://github.com/xujeff/tianti/issues/43#issue-3287851827 | Exploit |
Configurations
History
No history.
Information
Published : 2025-09-01 21:15
Updated : 2025-09-04 16:53
NVD link : CVE-2025-9795
Mitre link : CVE-2025-9795
CVE.ORG link : CVE-2025-9795
JSON object : View
Products Affected
tianti_project
- tianti
