High severity7.5NVD Advisory· Published May 5, 2025· Updated Jun 17, 2026
CVE-2025-45608
CVE-2025-45608
Description
Incorrect access control in the /system/user/findUserList API of Xinguan v0.0.1-SNAPSHOT allows attackers to access sensitive information via a crafted payload.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4cpe:2.3:a:zykzhangyukang:xinguan:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:zykzhangyukang:xinguan:*:*:*:*:*:*:*:*range: <=0.0.1-snapshot
- (no CPE)range: = 0.0.1-SNAPSHOT
Patches
Vulnerability mechanics
References
1- github.com/zykzhangyukang/Xinguan/issues/26nvdExploitIssue TrackingThird Party Advisory
News mentions
0No linked articles in our index yet.