Kaoshifeng's vulnerability profile centers on its Yunfan Learning Examination System, an educational platform where the identified issues center on authentication and access-control weaknesses, including improper authentication, insufficient authorization logic, privilege assignment flaws, and exposure of sensitive information to unauthorized actors. These patterns are typical of web-based educational software where authentication boundaries and session management demand careful implementation; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Kaoshifeng over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-13110HIGH A vulnerability classified as problematic has been found in Beijing Yunfan Internet Technology Yunfan Learning Examination System 1.9.2. Affected is an unknown function of the file | Jan 2, 2025 | 7.5 | 24 | NO | NO |
CVE-2024-13111HIGH A vulnerability classified as critical was found in Beijing Yunfan Internet Technology Yunfan Learning Examination System 1.9.2. Affected by this vulnerability is an unknown functi | Jan 2, 2025 | 8.1 | 22 | NO | NO |
CVE-2023-46963MEDIUM An issue in Beijing Yunfan Internet Technology Co., Ltd, Yunfan Learning Examination System v.6.5 allows a remote attacker to obtain sensitive information via the password paramete | Nov 4, 2023 | 5.3 | 17 | NO | NO |
CVE-2024-13109MEDIUM A vulnerability was found in Beijing Yunfan Internet Technology Yunfan Learning Examination System 1.9.2. It has been rated as critical. This issue affects some unknown processing | Jan 2, 2025 | 5.3 | 15 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Kaoshifeng.
Media articles that mention a CVE ID that affects a product developed by Kaoshifeng — matched by CVE ID, not by vendor name.