CVE-2025-9795 | xujeff tianti 天梯 up to 2.3 UploadController.java ajaxUploadFile upfile unrestricted upload (Issue 43)
A vulnerability marked as critical has been reported in xujeff tianti 天梯 up to 2.3. The impacted element is the function ajaxUploadFile of the file src/main/java/com/jeff/tianti/controller/UploadController.java. The manipulation of the argument upfile leads to unrestricted upload.
This vulnerability is traded as CVE-2025-9795. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.VulDB Recent EntriesRead More