Aaluoxiang
Aaluoxiang OA System: vulnerabilidades y CVE
Aaluoxiang OA System tiene 7 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE7
Últimos 12 meses0
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2025-44034 | Alta (8) | 0.49% | — | 16 sept 2025 | SQL injection vulnerability in oa_system oasys v.1.1 allows a remote attacker to execute arbitrary code via the alph parameters in src/main/Java/cn/gson/oasys/controller/address/AddrController |
| CVE-2025-29592 | Media (5.6) | 0.47% | — | 10 sept 2025 | oasys v1.1 is vulnerable to Directory Traversal in ProcedureController. |
| CVE-2025-44033 | Crítica (9.8) | 0.63% | — | 29 ago 2025 | SQL injection vulnerability in oa_system oasys v.1.1 allows a remote attacker to execute arbitrary code via the allDirector() method declaration in src/main/java/cn/gson/oasys/mappers/AddressMapper.java |
| CVE-2025-6829 | Media (5.3) | 0.40% | — | 28 jun 2025 | A vulnerability was found in aaluoxiang oa_system up to c3a08168c144f27256a90838492c713f55f1b207 and classified as critical. This issue affects the function outAddress of the component External Address Book Handler. The… |
| CVE-2025-5545 | Media (5.3) | 0.68% | — | 4 jun 2025 | A vulnerability classified as problematic has been found in aaluoxiang oa_system up to 5b445a6227b51cee287bd0c7c33ed94b801a82a5. This affects the function image of the file… |
| CVE-2025-5544 | Media (5.3) | 0.70% | — | 3 jun 2025 | A vulnerability was found in aaluoxiang oa_system up to 5b445a6227b51cee287bd0c7c33ed94b801a82a5. It has been rated as problematic. Affected by this issue is the function image of the file… |
| CVE-2025-1958 | Media (5.3) | 0.55% | — | 4 mar 2025 | A vulnerability, which was classified as critical, has been found in aaluoxiang oa_system 1.0. This issue affects some unknown processing of the file src/main/resources/mappers/address-mapper.xml. The manipulation of… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.