PT-2026-83981 · Unknown · Xuezhisi Open Source Exam System
CVE-2026-75460
·
Published
2026-08-31
·
Updated
2026-09-01
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
XueZhiSi Open Source Exam System versions prior to 3.9.1
Description
A privilege escalation issue exists in the teacher-end interface. The endpoint 'POST /api/teacher/user/page/list' allows the requester to fully control the
role parameter within the UserPageRequestVM object, potentially allowing a user to gain higher privileges.Recommendations
Update XueZhiSi Open Source Exam System to a version newer than 3.9.0.
As a temporary mitigation, restrict access to the 'POST /api/teacher/user/page/list' endpoint or avoid using the
role parameter in the UserPageRequestVM until the update is applied.Exploit
Fix
LPE
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Xuezhisi Open Source Exam System