CVE-2025-4012 is a server-side request forgery (SSRF) vulnerability affecting playeduxyz PlayEdu 开源培训系统 up to version 1.8. This flaw resides in the User Avatar Handler component, specifically when processing the 'Avatar' argument within the /api/backend/v1/user/create endpoint. With a CVSS score of 7.5 (HIGH), the vulnerability is easily exploitable remotely without authentication, potentially allowing attackers to make arbitrary requests from the server. While public exploit code exists, there is currently no evidence of active exploitation, and it has received minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.8CPE matchmatch criteria | cpe:2.3:a:playeduos:playedu:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.