CVE-2025-1958: aaluoxiang oa_system address-mapper.xml sql injection
A vulnerability, which was classified as critical, has been found in aaluoxiang oasystem 1.0. This issue affects some unknown processing of the file src/main/resources/mappers/address-mapper.xml. The manipulation of the argument outtype leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-1958?
CVE-2025-1958 is classified as a critical vulnerability.
How does CVE-2025-1958 affect the system?
CVE-2025-1958 allows for SQL injection through manipulation of the argument 'outtype' in the file address-mapper.xml.
What software is affected by CVE-2025-1958?
CVE-2025-1958 affects the aaluoxiang oa_system version 1.0.
How can I mitigate CVE-2025-1958?
Mitigation for CVE-2025-1958 involves sanitizing input parameters that interact with SQL queries.
Is there a patch available for CVE-2025-1958?
As of now, check with the vendor aaluoxiang for any security patches or updates addressing CVE-2025-1958.