CVE-2025-7939: Unrestricted Upload in jerryshensjf JPACookieShop 蛋糕商城JPA版
A vulnerability was found in jerryshensjf JPACookieShop 蛋糕商城JPA版 1.0. It has been classified as critical. Affected is the function addGoods of the file GoodsController.java. The manipulation leads to unrestricted upload. It is possible to launch the attack remotely.
CVE-2025-7939: Unrestricted Upload in jerryshensjf JPACookieShop 蛋糕商城JPA版
Description
A vulnerability was found in jerryshensjf JPACookieShop 蛋糕商城JPA版 1.0. It has been classified as critical. Affected is the function addGoods of the file GoodsController.java. The manipulation leads to unrestricted upload. It is possible to launch the attack remotely.
Technical Details
- Data Version
- 5.1
- Assigner Short Name
- VulDB
- Date Reserved
- 2025-07-21T07:13:54.228Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 687ea70ea83201eaac142c5a
Added to database: 7/21/2025, 8:46:06 PM
Last updated: 7/21/2025, 8:46:06 PM
Views: 1
Related Threats
CVE-2025-54122: CWE-918: Server-Side Request Forgery (SSRF) in Manager-io Manager
CriticalCVE-2025-54127: CWE-1188: Insecure Default Initialization of Resource in haxtheweb issues
CriticalCVE-2025-24938: Vulnerability in Nokia WaveSuite NOC
HighCVE-2025-24937: Vulnerability in Nokia WaveSuite NOC
CriticalCVE-2025-53832: CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') in translated lara-mcp
HighActions
Need enhanced features?
Contact root@offseq.com for Pro access with improved analysis and higher rate limits.