CVE-2025-3999: Seeyon Zhiyuan OA Web Application System URL Parameter date.jsp cross site scripting
A vulnerability, which was classified as problematic, has been found in Seeyon Zhiyuan OA Web Application System 8.1 SP2. This issue affects some unknown processing of the file seeyon\opt\Seeyon\A8\ApacheJetspeed\webapps\seeyon\common\js\addDate\date.jsp of the component URL Parameter Handler. The manipulation leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-3999?
CVE-2025-3999 is classified as a problematic vulnerability.
Which component is affected by CVE-2025-3999?
CVE-2025-3999 affects the file seeyon\opt\Seeyon\A8\ApacheJetspeed\webapps\seeyon\common\js\addDate\date.jsp within the Seeyon Zhiyuan OA Web Application System.
How do I fix CVE-2025-3999?
Fixing CVE-2025-3999 involves applying the latest security patches provided by Seeyon for the Zhiyuan OA Web Application.
What versions of Seeyon Zhiyuan OA Web Application System are impacted by CVE-2025-3999?
CVE-2025-3999 impacts Seeyon Zhiyuan OA Web Application System version 8.1 SP2 and potentially earlier versions.
Is user data at risk due to CVE-2025-3999?
Yes, CVE-2025-3999 may expose user data to unauthorized access if not addressed promptly.