CVE-2026-4284 Details
Description
A vulnerability was determined in taoofagi easegen-admin up to 8f87936ac774065b92fb20aab55b274a6ea76433. This issue affects the function downloadFile of the file - yudao-module-digitalcourse/yudao-module-digitalcourse-biz/src/main/java/cn/iocoder/yudao/module/digitalcourse/util/PPTUtil.java of the component PPT File Handler. This manipulation of the argument url causes server-side request forgery. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available. The vendor was contacted early about this disclosure but did not respond in any way.
A server-side request forgery (SSRF) vulnerability has been identified in the taoofagi easegen-admin application, specifically in versions prior to the commit 8f87936ac774065b92fb20aab55b274a6ea76433. The vulnerability resides in the PPT File Handler component, within the 'downloadFile' function of the 'PPTUtil.java' file. This issue allows remote attackers to manipulate the 'url' parameter, enabling them to send requests from the server to arbitrary internal or external destinations. The vulnerability has been publicly disclosed and is exploitable by authenticated users.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Mar 16, 2026CISA-ADP
Assessed Mar 17, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://fx4tqqfvdw4.feishu.cn/docx/XF5WdvWAEoU9jyx2C2mcImSMnBg?from=from_copylink | [email protected] | ExploitPartial Content |
| https://vuldb.com/?ctiid.351290 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/?id.351290 | [email protected] | AdvisoryExploitPartial Content |
| https://vuldb.com/?submit.771949 | [email protected] | Technical Description |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-918 | Server-Side Request Forgery (SSRF) | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| taoofagi easegen-admin | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 29, 2026 | Data Remediation | [email protected] |
| Mar 16, 2026 | New CVE Received | [email protected] |
Volerion