← volver
CVE-2025-13209

bestfeng oa_git_free WorkflowPredefineController.java updateWriteBack xml external entity reference

CVSS 5.3 MEDIUMEPSS 0.3%CWE-610CWE-611
Vexday Risk Score
13Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS 5.3EPSS 0.3%KEV nãoPoC Nuclei Metasploit Patch
Ciclo de vida
15 nov 2025Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
A weakness has been identified in bestfeng oa_git_free up to 9.5. This affects the function updateWriteBack of the file yimioa-oa9.5\server\c-flow\src\main\java\com\cloudweb\oa\controller\WorkflowPredefineController.java. This manipulation of the argument writeProp causes xml external entity reference. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be exploited.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
Productos afectados
bestfeng · oa_git_free

¿Quieres saber si tu infraestructura está expuesta a esto?

Hablar con TrueHacking →