5.3
/ 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X
Description
A vulnerability was found in jerryshensjf JPACookieShop 蛋糕商城JPA版 1.0. It has been classified as critical. Affected is the function addGoods of the file GoodsController.java. The manipulation leads to unrestricted upload. It is possible to launch the attack remotely.
Basic Information
ID
CVE-2025-7939
Source
VulDB
Published
Jul 21, 2025 at 20:32
Modified
Jul 22, 2025 at 16:05
Affected Product
Vendor
jerryshensjf
Product
JPACookieShop 蛋糕商城JPA版
Version
1.0
Affected Versions
jerryshensjf JPACookieShop 蛋糕商城JPA版 1.0