CVE-2025-5544: aaluoxiang oa_system UserpanelController.java image path traversal
A vulnerability was found in aaluoxiang oasystem up to 5b445a6227b51cee287bd0c7c33ed94b801a82a5. It has been rated as problematic. Affected by this issue is the function image of the file src/main/java/cn/gson/oasys/controller/user/UserpanelController.java. The manipulation leads to path traversal. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-5544?
CVE-2025-5544 is rated as problematic.
How do I fix CVE-2025-5544?
To fix CVE-2025-5544, update the aaluoxiang oa_system to a version higher than 5b445a6227b51cee287bd0c7c33ed94b801a82a5.
What component is affected by CVE-2025-5544?
CVE-2025-5544 affects the image function in the UserpanelController.java file.
What software is affected by CVE-2025-5544?
CVE-2025-5544 affects aaluoxiang oa_system versions up to 5b445a6227b51cee287bd0c7c33ed94b801a82a5.
Is CVE-2025-5544 exploitable remotely?
Details regarding the remote exploitability of CVE-2025-5544 are not specified.