CVE-2025-3388: hailey888 oa_system Frontend LoginsController.java loginCheck cross site scripting
A vulnerability classified as problematic was found in hailey888 oasystem up to 2025.01.01. This vulnerability affects the function loginCheck of the file cn/gson/oasys/controller/login/LoginsController.java of the component Frontend. The manipulation of the argument Username leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-3388?
CVE-2025-3388 is classified as problematic.
How do I fix CVE-2025-3388?
To fix CVE-2025-3388, upgrade the hailey888 oa_system to a version later than 2025.01.01.
What component is affected by CVE-2025-3388?
CVE-2025-3388 affects the Frontend component, specifically the function loginCheck in LoginsController.java.
What type of vulnerability is CVE-2025-3388?
CVE-2025-3388 is categorized as a problematic vulnerability due to argument manipulation in the login process.
Who is the vendor for the vulnerable product related to CVE-2025-3388?
The vendor for the vulnerable product related to CVE-2025-3388 is hailey888.