CVE-2026-75460

Medium severity, CVSS 6.5. EPSS: 0.3% chance of exploitation in the next 30 days.

XueZhiSi Open Source Exam System <= 3.9.0 has a privilege escalation vulnerability in the teacher-end interface POST /api/teacher/user/page/list. The role parameter in UserPageRequestVM is fully controllable by the requester.

Published 2026-08-31. Last modified 2026-09-01.