📦 Platform

by Fuyang Lipengjun

🔍 What is Platform?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-57210

HIGH CVSS 7.5 Dec 4, 2025

This vulnerability allows attackers to bypass access controls in the ApiPayController component of platform v1.0.0, potentially exposing sensitive information. Any system running the vulnerable versio...

CVE-2025-57212

HIGH CVSS 7.5 Dec 4, 2025

This vulnerability in the ApiOrderService.java component of platform v1.0.0 allows attackers to bypass access controls and retrieve sensitive information through specially crafted requests. It affects...

CVE-2025-57213

HIGH CVSS 7.5 Dec 4, 2025

This vulnerability allows attackers to bypass access controls in the orderService.queryObject component of platform v1.0.0, enabling unauthorized access to sensitive information. Attackers can exploit...

CVE-2025-10822

MEDIUM CVSS 4.3 Sep 23, 2025

CVE-2025-10822 is an improper authorization vulnerability in the fuyang_lipengjun platform 1.0 that allows unauthorized access to SMS log data via the SysSmsLogController function. Attackers can remot...

CVE-2025-10821

MEDIUM CVSS 4.3 Sep 22, 2025

This vulnerability allows unauthorized access to topic category data in fuyang_lipengjun platform 1.0 due to improper authorization in the TopicCategoryController. Attackers can remotely exploit this ...

CVE-2025-10820

MEDIUM CVSS 4.3 Sep 22, 2025

This vulnerability in the fuyang_lipengjun platform 1.0 allows unauthorized access to the TopicController's queryAll function, enabling attackers to retrieve topic data without proper authentication. ...

CVE-2025-10819

MEDIUM CVSS 4.3 Sep 22, 2025

This vulnerability in fuyang_lipengjun platform 1.0 allows unauthorized access to user coupon data through the UserCouponController queryAll function. Attackers can exploit this to view sensitive coup...

CVE-2025-10676

MEDIUM CVSS 4.3 Sep 18, 2025

This vulnerability in fuyang_lipengjun platform 1.0 allows improper authorization through the BrandController function at /brand/queryAll. Attackers can remotely exploit this weakness to access unauth...

CVE-2025-10674

MEDIUM CVSS 4.3 Sep 18, 2025

CVE-2025-10674 is an improper authorization vulnerability in the fuyang_lipengjun platform 1.0 that allows attackers to access the /attributecategory/queryAll endpoint without proper permissions. This...

CVE-2025-10675

MEDIUM CVSS 4.3 Sep 18, 2025

This vulnerability in fuyang_lipengjun platform 1.0 allows improper authorization via the AttributeController function at /attribute/queryAll, enabling unauthorized access to sensitive data or functio...

CVE-2025-10086

MEDIUM CVSS 6.3 Sep 8, 2025

CVE-2025-10086 is an improper authorization vulnerability in the fuyang_lipengjun platform 1.0.0 that allows remote attackers to access unauthorized functionality via the queryAll function in the AdPo...

CVE-2025-7936

MEDIUM CVSS 6.3 Jul 21, 2025

This critical SQL injection vulnerability in the fuyang_lipengjun platform allows remote attackers to execute arbitrary SQL commands via the beanName/methodName parameters in the ScheduleJobLogControl...

CVE-2025-7934

MEDIUM CVSS 6.3 Jul 21, 2025

This CVE describes a critical SQL injection vulnerability in the fuyang_lipengjun platform's ScheduleJobController. Attackers can exploit this by manipulating the beanName parameter in the queryPage f...