CVE-2025-4529: Seeyon Zhiyuan OA Web Application System ZIP File M3CoreController.class download path traversal
A vulnerability was found in Seeyon Zhiyuan OA Web Application System 8.1 SP2. It has been classified as problematic. Affected is the function Download of the file seeyon\opt\Seeyon\A8\ApacheJetspeed\webapps\seeyon\WEB-INF\lib\seeyon-apps-m3.jar!\com\seeyon\apps\m3\core\controller\M3CoreController.class of the component ZIP File Handler. The manipulation of the argument Name leads to path traversal. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-4529?
CVE-2025-4529 is classified as a problematic vulnerability in the Seeyon Zhiyuan OA Web Application System.
How do I fix CVE-2025-4529?
To fix CVE-2025-4529, update to the latest version of Seeyon Zhiyuan OA Web Application System that addresses this vulnerability.
Which versions of Seeyon Zhiyuan OA Web Application System are affected by CVE-2025-4529?
CVE-2025-4529 affects Seeyon Zhiyuan OA Web Application System version 8.1 SP2.
What component of Seeyon Zhiyuan OA Web Application System is vulnerable in CVE-2025-4529?
CVE-2025-4529 affects the Download function within the seeyon-apps-m3.jar file of the application.
Is CVE-2025-4529 being actively exploited?
As of now, there are no reported incidents confirming active exploitation of CVE-2025-4529.