CVE-2025-15503: Sangfor Operation and Maintenance Management System common.jsp unrestricted upload
A security flaw has been discovered in Sangfor Operation and Maintenance Management System up to 3.0.8. The impacted element is an unknown function of the file /fort/trust/version/common/common.jsp. Performing a manipulation of the argument File results in unrestricted upload. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-15503?
CVE-2025-15503 is classified with a high severity due to its potential for unauthorized file uploads.
How do I fix CVE-2025-15503?
To mitigate CVE-2025-15503, update the Sangfor Operation and Maintenance Management System to version 3.0.9 or later.
What vulnerabilities are associated with CVE-2025-15503?
CVE-2025-15503 can lead to unauthorized file upload which may compromise the affected system.
Which versions of Sangfor Operation and Maintenance Management System are affected by CVE-2025-15503?
All versions up to and including 3.0.8 of Sangfor Operation and Maintenance Management System are affected by CVE-2025-15503.
What is the impact of CVE-2025-15503 on system security?
CVE-2025-15503 allows attackers to perform unrestricted file uploads, which can lead to further exploitation of the system.