CVE-2023-7335: EduSoho < 22.4.7 Arbitrary File Read via classroom-course-statistics
EduSoho versions prior to 22.4.7 contain an arbitrary file read vulnerability in the classroom-course-statistics export functionality. A remote, unauthenticated attacker can supply crafted path traversal sequences in the fileNames[] parameter to read arbitrary files from the server filesystem, including application configuration files such as config/parameters.yml that may contain secrets and database credentials. Exploitation evidence was observed by the Shadowserver Foundation on 2026-01-19 (UTC).
Security readout for executives and security teams
Plain-English summary
EduSoho servers before 22.4.7 may let an unauthenticated internet user read files from the server. The main business risk is exposure of configuration secrets and database credentials, which can turn a file-read flaw into broader compromise.
Executive priority
Treat this as urgent for any public EduSoho deployment. The flaw is unauthenticated, confidentiality-focused, and tied to reported exploitation evidence, so delaying remediation risks credential exposure and follow-on intrusion.
Technical view
The classroom-course-statistics export function accepts user-controlled fileNames[] values without sufficient path traversal protection, enabling arbitrary server-side file reads. The CVSS 4.0 score is 8.7, with network access, low complexity, no privileges, no user interaction, and high confidentiality impact.
Likely exposure
Organizations running internet-accessible EduSoho instances before 22.4.7 are the primary concern. Exposure should be confirmed by asset inventory and version checks because the affected metadata in the bundle is sparse.
Exploitation context
The bundle reports exploitation evidence observed by Shadowserver on 2026-01-19 UTC. The CVE is not listed as KEV. Public references include technical writeups and exploit-tagged material, increasing operational risk.
Researcher notes
Do not rely solely on the affected CPE data; it appears limited. Focus validation on EduSoho version, route exposure, export behavior, and evidence of sensitive file access. Avoid reproducing public exploit procedures in production.
Mitigation direction
Upgrade EduSoho to version 22.4.7 or later.
Review EduSoho vendor guidance for any additional hardening steps.
Rotate application secrets and database credentials if exposure is suspected.
Restrict public access to EduSoho administrative or export functions where feasible.
Review logs for suspicious classroom-course-statistics export requests.
Validation and detection
Inventory EduSoho deployments and identify versions below 22.4.7.
Confirm whether classroom-course-statistics export functionality is internet-accessible.
Check server logs for anomalous fileNames[] traversal patterns.
Review whether sensitive configuration files were accessed.
Verify patched systems no longer expose the vulnerable behavior.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cwe · medium confidence lookup
CWE-22: File access and web shell behavior lookup
File traversal and upload weaknesses can lead teams to review file, web shell, execution, and collection telemetry. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.
The CVE wording references database injection or access, so collection and exfiltration review may help. This is a Glexia inferred lookup path, not an official MITRE, ATT&CK, or CVE Program mapping.
The CVE wording references file access or upload behavior, so file telemetry and web shell review may help. This is a Glexia inferred lookup path, not an official MITRE, ATT&CK, or CVE Program mapping.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.