CVE-2025-4012
CVSS 3.1 Score 7.5 of 10 (high)
Details
Published Apr 28, 2025
Updated: May 12, 2025
CWE ID 918
Summary
CVE-2025-4012 is a newly disclosed vulnerability affecting PlayEdu 开源培训系统 version 1.8 and below. This issue lies in the User Avatar Handler component, specifically within the /api/backend/v1/user/create endpoint. The manipulation of an argument named "Avatar" can lead to server-side request forgery, enabling an attacker to initiate unauthorized requests. Although the exact impact and exploit details are unknown, public disclosure indicates that remote exploitation is possible. The vendor has been notified but has yet to respond.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.