yimioa
Products
1- 9 CVEs
Recent CVEs
9| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-36605 | Cri | 0.64 | 9.8 | 0.01 | Aug 19, 2022 | Yimioa v6.1 was discovered to contain a SQL injection vulnerability via the orderbyGET parameter. | ||
| CVE-2025-25589 | Hig | 0.53 | 8.1 | 0.00 | Mar 18, 2025 | An XML external entity (XXE) injection vulnerability in the component /weixin/aes/XMLParse.java of yimioa before v2024.07.04 allows attackers to execute arbitrary code via supplying a crafted XML file. | ||
| CVE-2025-25585 | Hig | 0.47 | 7.3 | 0.00 | Mar 18, 2025 | Incorrect access control in the component /config/WebSecurityConfig.java of yimioa before v2024.07.04 allows unauthorized attackers to arbitrarily modify Administrator passwords. | ||
| CVE-2025-1225 | Med | 0.41 | 6.3 | 0.00 | Feb 12, 2025 | A vulnerability, which was classified as problematic, has been found in ywoa up to 2024.07.03. This issue affects the function extract of the file c-main/src/main/java/com/redmoon/weixin/aes/XMLParse.java of the component WXCallBack Interface. The manipulation leads to xml… | ||
| CVE-2025-25582 | Med | 0.40 | 6.1 | 0.00 | Mar 18, 2025 | yimioa before v2024.07.04 was discovered to contain a SQL injection vulnerability via the selectNoticeList() method at /xml/OaNoticeMapper.xml. | ||
| CVE-2025-25590 | Med | 0.40 | 6.1 | 0.00 | Mar 18, 2025 | yimioa before v2024.07.04 was discovered to contain a SQL injection vulnerability via the component /mapper/xml/AddressDao.xml. | ||
| CVE-2025-25580 | Med | 0.40 | 6.1 | 0.00 | Mar 18, 2025 | yimioa before v2024.07.04 was discovered to contain a SQL injection vulnerability via the listNameBySql() method at /xml/UserMapper.xml. | ||
| CVE-2025-1226 | Med | 0.35 | 5.3 | 0.01 | Feb 12, 2025 | A vulnerability was found in ywoa up to 2024.07.03. It has been declared as critical. This vulnerability affects unknown code of the file /oa/setup/setup.jsp. The manipulation leads to improper authorization. The attack can be initiated remotely. The exploit has been disclosed… | ||
| CVE-2025-25586 | Med | 0.27 | 4.2 | 0.00 | Mar 18, 2025 | yimioa before v2024.07.04 was discovered to contain an information disclosure vulnerability via the component /resources/application.yml. |
- risk 0.64cvss 9.8epss 0.01
Yimioa v6.1 was discovered to contain a SQL injection vulnerability via the orderbyGET parameter.
- risk 0.53cvss 8.1epss 0.00
An XML external entity (XXE) injection vulnerability in the component /weixin/aes/XMLParse.java of yimioa before v2024.07.04 allows attackers to execute arbitrary code via supplying a crafted XML file.
- risk 0.47cvss 7.3epss 0.00
Incorrect access control in the component /config/WebSecurityConfig.java of yimioa before v2024.07.04 allows unauthorized attackers to arbitrarily modify Administrator passwords.
- risk 0.41cvss 6.3epss 0.00
A vulnerability, which was classified as problematic, has been found in ywoa up to 2024.07.03. This issue affects the function extract of the file c-main/src/main/java/com/redmoon/weixin/aes/XMLParse.java of the component WXCallBack Interface. The manipulation leads to xml…
- risk 0.40cvss 6.1epss 0.00
yimioa before v2024.07.04 was discovered to contain a SQL injection vulnerability via the selectNoticeList() method at /xml/OaNoticeMapper.xml.
- risk 0.40cvss 6.1epss 0.00
yimioa before v2024.07.04 was discovered to contain a SQL injection vulnerability via the component /mapper/xml/AddressDao.xml.
- risk 0.40cvss 6.1epss 0.00
yimioa before v2024.07.04 was discovered to contain a SQL injection vulnerability via the listNameBySql() method at /xml/UserMapper.xml.
- risk 0.35cvss 5.3epss 0.01
A vulnerability was found in ywoa up to 2024.07.03. It has been declared as critical. This vulnerability affects unknown code of the file /oa/setup/setup.jsp. The manipulation leads to improper authorization. The attack can be initiated remotely. The exploit has been disclosed…
- risk 0.27cvss 4.2epss 0.00
yimioa before v2024.07.04 was discovered to contain an information disclosure vulnerability via the component /resources/application.yml.