CVE-2025-44034: SQL Injection
Published Sep 16, 2025
·Updated
SQL injection vulnerability in oasystem oasys v.1.1 allows a remote attacker to execute arbitrary code via the alph parameters in src/main/Java/cn/gson/oasys/controller/address/AddrController
Affected Software
2 affected components
oa_system oasys
aaluoxiang Oa System=1.1
Event History
Sep 16, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-44034?
CVE-2025-44034 is classified as a high-severity SQL injection vulnerability.
2
How do I fix CVE-2025-44034?
To fix CVE-2025-44034, validate and sanitize the 'alph' parameters in the application to prevent SQL injection.
3
Who is affected by CVE-2025-44034?
CVE-2025-44034 affects users of the oa_system oasys version 1.1.
4
What types of attacks can CVE-2025-44034 enable?
CVE-2025-44034 can allow remote attackers to execute arbitrary code on the affected system.
5
Is CVE-2025-44034 easy to exploit?
CVE-2025-44034 is relatively easy to exploit, especially for attackers familiar with SQL injection techniques.