CVE-2025-11321 MEDIUM

CVE-2025-11321: zhuimengshaonian wisdom-education WrongBookController.java authorization

Vendor Zhuimengshaonian
Product wisdom-education
Weakness CWE-639 · IDOR
Published October 6, 2025
Last update October 6, 2025

CVSS base score

5.3/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P

What the vulnerability does

Description

A vulnerability was detected in zhuimengshaonian wisdom-education up to 1.0.4. The affected element is an unknown function of the file src/main/java/com/education/api/controller/student/WrongBookController.java. Performing manipulation of the argument subjectId results in authorization bypass. The attack can be initiated remotely. The exploit is now public and may be used.

Key dates

Disclosure timeline

October 6, 2025 CVE published
October 6, 2025 Record updated