Export CSV

Products

1 vendor
VendorProductsCVEsKEVAvg EPSSWorst Severity
110022.9%HIGH

Related CVEs

10
CVE IDDescriptionSeverityCVSSKEVEPSSPublished
CVE-2025-25586yimioa before v2024.07.04 was discovered to contain an information disclosure vulnerability via the component /resources/application.yml.MEDIUM4.24.0%Mar 18, 2025
CVE-2025-25582yimioa before v2024.07.04 was discovered to contain a SQL injection vulnerability via the selectNoticeList() method at /xml/OaNoticeMapper.xml.MEDIUM6.17.1%Mar 18, 2025
CVE-2025-25590yimioa before v2024.07.04 was discovered to contain a SQL injection vulnerability via the component /mapper/xml/AddressDao.xml.MEDIUM6.17.9%Mar 18, 2025
CVE-2025-25585Incorrect access control in the component /config/WebSecurityConfig.java of yimioa before v2024.07.04 allows unauthorized attackers to arbitrarily modify Administrator passwords.HIGH7.317.0%Mar 18, 2025
CVE-2025-25580yimioa before v2024.07.04 was discovered to contain a SQL injection vulnerability via the listNameBySql() method at /xml/UserMapper.xml.MEDIUM6.17.9%Mar 18, 2025
CVE-2025-1227A vulnerability was found in ywoa up to 2024.07.03. It has been rated as critical. This issue affects the function selectList of the file com/cloudweb/oa/mapper/xml/AddressDao.xml. The manipulation leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 2024.07.04 is able to address this issue. It is recommended to upgrade the affected component.MEDIUM5.338.1%Feb 12, 2025
CVE-2025-1226A vulnerability was found in ywoa up to 2024.07.03. It has been declared as critical. This vulnerability affects unknown code of the file /oa/setup/setup.jsp. The manipulation leads to improper authorization. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 2024.07.04 is able to address this issue. It is recommended to upgrade the affected component.MEDIUM6.950.9%Feb 12, 2025
CVE-2025-1225A vulnerability, which was classified as problematic, has been found in ywoa up to 2024.07.03. This issue affects the function extract of the file c-main/src/main/java/com/redmoon/weixin/aes/XMLParse.java of the component WXCallBack Interface. The manipulation leads to xml external entity reference. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 2024.07.04 is able to address this issue. It is recommended to upgrade the affected component.MEDIUM5.327.1%Feb 12, 2025
CVE-2025-1224A vulnerability classified as critical was found in ywoa up to 2024.07.03. This vulnerability affects the function listNameBySql of the file com/cloudweb/oa/mapper/xml/UserMapper.xml. The manipulation leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 2024.07.04 is able to address this issue. It is recommended to upgrade the affected component.MEDIUM5.330.7%Feb 12, 2025
CVE-2025-1216A vulnerability, which was classified as critical, has been found in ywoa up to 2024.07.03. This issue affects the function selectNoticeList of the file com/cloudweb/oa/mapper/xml/OaNoticeMapper.xml. The manipulation of the argument sort leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 2024.07.04 is able to address this issue. It is recommended to upgrade the affected component.MEDIUM5.338.6%Feb 12, 2025