Beveiligingsadvies

CVE-2026-75460

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-08-31 00:00:00
Laatst bijgewerkt 2026-09-01 19:35:37
Toegewezen door mitre
CVSS-score 6.5
Status PUBLISHED

Beschrijving

XueZhiSi Open Source Exam System <= 3.9.0 has a privilege escalation vulnerability in the teacher-end interface POST /api/teacher/user/page/list. The role parameter in UserPageRequestVM is fully controllable by the requester.