CVE-2025-4012

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Apr 28, 2025
Updated: May 12, 2025
CWE ID 918

Summary

CVE-2025-4012 is a newly disclosed vulnerability affecting PlayEdu 开源培训系统 version 1.8 and below. This issue lies in the User Avatar Handler component, specifically within the /api/backend/v1/user/create endpoint. The manipulation of an argument named "Avatar" can lead to server-side request forgery, enabling an attacker to initiate unauthorized requests. Although the exact impact and exploit details are unknown, public disclosure indicates that remote exploitation is possible. The vendor has been notified but has yet to respond.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share