CVE-2026-75460
EUVD-2026-6888031.08.2026, 21:17
XueZhiSi Open Source Exam System <= 3.9.0 has a privilege escalation vulnerability in the teacher-end interface POST /api/teacher/user/page/list. The role parameter in UserPageRequestVM is fully controllable by the requester.Enginsight
Awaiting analysis
This vulnerability is currently awaiting analysis.