4.3
CVSSv3

CVE-2025-5545

CVSSv4: 5.3 | CVSSv3: 4.3 | CVSSv2: 4 | VMScore: 630 | EPSS: 0.00086 | KEV: Not Included
Published: 04/06/2025 Updated: 04/06/2025

Vulnerability Summary

Remote Path Traversal Vulnerability in aaluoxiang oa_system Controller

A path traversal vulnerability exists in aaluoxiang oa_system up to version 5b445a6227b51cee287bd0c7c33ed94b801a82a5. The issue is located in the image function within the ProcedureController.java file. An attacker can remotely manipulate this vulnerability to potentially access unauthorized files or directories. The vulnerability details have been publicly disclosed, and there is a possibility that the exploit could be used. Since the product does not use versioning, determining the exact affected or unaffected releases is not possible.

Vulnerable Product Search on Vulmon Subscribe to Product

aaluoxiang oa system