CVE-2025-31339

MEDIUM

Wisdom Master Pro <5.3 - File Upload

Title source: llm
STIX 2.1

Description

An unrestricted upload of file with dangerous type vulnerability in the course management function of Wisdom Master Pro versions 5.0 through 5.2 allows remote authenticated users to craft a malicious file.

References (1)

Core 1
Core References
Vendor Advisory third-party-advisory
https://zuso.ai/advisory/za-2025-02

Scores

CVSS v4 5.3
EPSS 0.0076
EPSS Percentile 73.5%
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-434
Status published
Products (1)
SUNNET Technology Co., Ltd./Wisdom Master Pro 5.0 - 5.2
Published Apr 17, 2025
Tracked Since Feb 18, 2026