CVE-2025-5140: Seeyon Zhiyuan OA Web Application System ThirdMenuController.class this.oursNetService.getData server-side request forgery
A vulnerability classified as critical has been found in Seeyon Zhiyuan OA Web Application System up to 8.1 SP2. This affects the function this.oursNetService.getData of the file com\ours\www\ehr\openPlatform1\open4ClientType\controller\ThirdMenuController.class. The manipulation of the argument url leads to server-side request forgery. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-5140?
CVE-2025-5140 is classified as a critical vulnerability.
What version of the Seeyon Zhiyuan OA Web Application System is affected by CVE-2025-5140?
CVE-2025-5140 affects Seeyon Zhiyuan OA Web Application System versions up to 8.1 SP2.
How do I fix CVE-2025-5140?
To fix CVE-2025-5140, update the Seeyon Zhiyuan OA Web Application System to a version beyond 8.1 SP2.
What component of Seeyon Zhiyuan OA Web Application System is vulnerable in CVE-2025-5140?
CVE-2025-5140 affects the function this.oursNetService.getData in the ThirdMenuController class.
What are the implications of CVE-2025-5140?
CVE-2025-5140 could allow unauthorized access or manipulation of sensitive data in the affected system.