Key Information Summary Vulnerability Description Vulnerability Type: Horizontal Privilege Escalation Affected Version: wisdom-education 1.0.4 Description: Attackers can view others' information by modifying the parameter. Vulnerability Analysis Vulnerable Class File: Problematic Code Snippet: Issue in SQL Query: Root Cause: The query primarily relies on , which is passed via the model without any filtering, allowing unauthorized access to others' data. Vulnerability Reproduction POC: Summary Key Point: The parameter is directly used in SQL queries without filtering, leading to a horizontal privilege escalation vulnerability. Remediation Recommendation: Implement strict validation and filtering for the parameter to ensure it only contains valid values.