CVE-2025-15446: Seeyon Zhiyuan OA Web Application System fixedAssetsList.j%73p sql injection
Rejected reason: REJECT DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: The vendor mentioned in the original disclosure filed a report that this issue affects a different vendor. The researcher was not able to provide a proof for his disputed claim which is why the CNA decided to revoke the whole entry.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-15446?
The severity of CVE-2025-15446 is critical due to the potential for SQL injection vulnerabilities in the Seeyon Zhiyuan OA Web Application System.
How do I fix CVE-2025-15446?
To fix CVE-2025-15446, ensure you apply the latest security patches from Seeyon for versions up to 20251223.
What causes CVE-2025-15446?
CVE-2025-15446 is caused by insufficient input validation leading to SQL injection via manipulated arguments in the file /assetsGroupReport/fixedAssetsList.j%73p.
Who is affected by CVE-2025-15446?
CVE-2025-15446 affects users of the Seeyon Zhiyuan OA Web Application System up to version 20251223.
Can CVE-2025-15446 be exploited remotely?
Yes, CVE-2025-15446 can be exploited remotely by attackers manipulating the unitCode argument.