Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-26359 | A vulnerability has been found in xujeff tianti 天梯 up to 2.3. The impacted element is the function ajaxUploadFile of the file src/main/java/com/jeff/tianti/controller/UploadController.java. The manipulation of the argument upfile leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. |
Thu, 04 Sep 2025 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:tianti_project:tianti:*:*:*:*:*:*:*:* |
Tue, 02 Sep 2025 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Tianti Project
Tianti Project tianti |
|
| Vendors & Products |
Tianti Project
Tianti Project tianti |
Tue, 02 Sep 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 01 Sep 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability has been found in xujeff tianti 天梯 up to 2.3. The impacted element is the function ajaxUploadFile of the file src/main/java/com/jeff/tianti/controller/UploadController.java. The manipulation of the argument upfile leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. | |
| Title | xujeff tianti 天梯 UploadController.java ajaxUploadFile unrestricted upload | |
| Weaknesses | CWE-284 CWE-434 |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2025-09-02T15:08:37.422Z
Reserved: 2025-09-01T11:38:37.454Z
Link: CVE-2025-9795
Updated: 2025-09-02T13:43:42.530Z
Status : Analyzed
Published: 2025-09-01T21:15:29.607
Modified: 2026-04-29T01:00:01.613
Link: CVE-2025-9795
No data.
OpenCVE Enrichment
Updated: 2025-09-02T15:23:09Z
EUVD