Answer in brief
CVE-2023-7335 records a High severity (CVSS 8.7) vulnerability in EduSoho < 22.4.7 Arbitrary File Read via classroom-course-statistics. The current sources do not mark it as known exploited. The current feed maps Hangzhou Kuozhi Network Technology Co., Ltd./EduSoho (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
Answer in brief
CVE-2023-7335 records a High severity (CVSS 8.7) vulnerability in EduSoho < 22.4.7 Arbitrary File Read via classroom-course-statistics. The current sources do not mark it as known exploited. The current feed maps Hangzhou Kuozhi Network Technology Co., Ltd./EduSoho (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 8.7. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Hangzhou Kuozhi Network Technology Co., Ltd./EduSoho (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Hangzhou Kuozhi Network Technology Co., Ltd./EduSohogeneric | >=0 <22.4.7 | 22.4.7 |
Published upstream
Jan 22, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Jul 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Jul 15, 2026
EduSoho versions prior to 22.4.7 contain an arbitrary file read vulnerability in the classroom-course-statistics export functionality. A remote, unauthenticated attacker can supply crafted path traversal sequences in the fileNames[] parameter to read arbitrary files from the server filesystem, including application configuration files such as config/parameters.yml that may contain secrets and database credentials. Exploitation evidence was observed by the Shadowserver Foundation on 2026-01-19 (UTC).
Quoted source text, attributed separately from HOL analysis.
CVSS is 8.7. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Hangzhou Kuozhi Network Technology Co., Ltd./EduSoho (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Hangzhou Kuozhi Network Technology Co., Ltd./EduSohogeneric | >=0 <22.4.7 | 22.4.7 |
Published upstream
Jan 22, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Jul 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Jul 15, 2026
EduSoho versions prior to 22.4.7 contain an arbitrary file read vulnerability in the classroom-course-statistics export functionality. A remote, unauthenticated attacker can supply crafted path traversal sequences in the fileNames[] parameter to read arbitrary files from the server filesystem, including application configuration files such as config/parameters.yml that may contain secrets and database credentials. Exploitation evidence was observed by the Shadowserver Foundation on 2026-01-19 (UTC).
Quoted source text, attributed separately from HOL analysis.