CVE-2025-15447: Seeyon Zhiyuan OA Web Application System assetsService.j%73p sql injection
Rejected reason: REJECT DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: The vendor mentioned in the original disclosure filed a report that this issue affects a different vendor. The researcher was not able to provide a proof for his disputed claim which is why the CNA decided to revoke the whole entry.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-15447?
CVE-2025-15447 has a high severity due to its potential for SQL injection attacks, which can compromise database security.
How do I fix CVE-2025-15447?
To fix CVE-2025-15447, update the Seeyon Zhiyuan OA Web Application System to a version released after 20251223.
What systems are affected by CVE-2025-15447?
CVE-2025-15447 affects the Seeyon Zhiyuan OA Web Application System versions up to and including 20251223.
What type of vulnerability is CVE-2025-15447?
CVE-2025-15447 is classified as an SQL injection vulnerability, allowing attackers to manipulate database queries.
How can CVE-2025-15447 impact my organization?
CVE-2025-15447 can allow attackers to execute unauthorized database commands, leading to data loss or leakage and potential compliance issues.