← Database

CVE-2026-75460

MEDIUM CVSS: 6.5 Published: 2026-08-31 Modified: 2026-09-01

Description

XueZhiSi Open Source Exam System <= 3.9.0 has a privilege escalation vulnerability in the teacher-end interface POST /api/teacher/user/page/list. The role parameter in UserPageRequestVM is fully controllable by the requester.

Affected Platforms

Unknown

Weakness Type

CWE-639

References