VYPR

yimioa

by yimioa

CVEs (9)

  • CVE-2022-36605CriAug 19, 2022
    risk 0.64cvss 9.8epss 0.01

    Yimioa v6.1 was discovered to contain a SQL injection vulnerability via the orderbyGET parameter.

  • CVE-2025-25589HigMar 18, 2025
    risk 0.53cvss 8.1epss 0.00

    An XML external entity (XXE) injection vulnerability in the component /weixin/aes/XMLParse.java of yimioa before v2024.07.04 allows attackers to execute arbitrary code via supplying a crafted XML file.

  • CVE-2025-25585HigMar 18, 2025
    risk 0.47cvss 7.3epss 0.00

    Incorrect access control in the component /config/WebSecurityConfig.java of yimioa before v2024.07.04 allows unauthorized attackers to arbitrarily modify Administrator passwords.

  • CVE-2025-1225MedFeb 12, 2025
    risk 0.41cvss 6.3epss 0.00

    A vulnerability, which was classified as problematic, has been found in ywoa up to 2024.07.03. This issue affects the function extract of the file c-main/src/main/java/com/redmoon/weixin/aes/XMLParse.java of the component WXCallBack Interface. The manipulation leads to xml…

  • CVE-2025-25582MedMar 18, 2025
    risk 0.40cvss 6.1epss 0.00

    yimioa before v2024.07.04 was discovered to contain a SQL injection vulnerability via the selectNoticeList() method at /xml/OaNoticeMapper.xml.

  • CVE-2025-25590MedMar 18, 2025
    risk 0.40cvss 6.1epss 0.00

    yimioa before v2024.07.04 was discovered to contain a SQL injection vulnerability via the component /mapper/xml/AddressDao.xml.

  • CVE-2025-25580MedMar 18, 2025
    risk 0.40cvss 6.1epss 0.00

    yimioa before v2024.07.04 was discovered to contain a SQL injection vulnerability via the listNameBySql() method at /xml/UserMapper.xml.

  • CVE-2025-1226MedFeb 12, 2025
    risk 0.35cvss 5.3epss 0.01

    A vulnerability was found in ywoa up to 2024.07.03. It has been declared as critical. This vulnerability affects unknown code of the file /oa/setup/setup.jsp. The manipulation leads to improper authorization. The attack can be initiated remotely. The exploit has been disclosed…

  • CVE-2025-25586MedMar 18, 2025
    risk 0.27cvss 4.2epss 0.00

    yimioa before v2024.07.04 was discovered to contain an information disclosure vulnerability via the component /resources/application.yml.