CVE-2025-2114

CVSS 3.1 Score 3.7 of 10 (low)

Details

Published Mar 9, 2025
CWE ID 285
CWE ID 266

Summary

CVE-2025-2114 is a recently disclosed vulnerability affecting the Shenzhen Sixun Software Shanghui Group Business Management System 7. This issue lies in the processing of the file /WebPages/Adm/OperatorStop.asp within the Reset Password Interface. An improper authorization flaw is triggered by the manipulation of the OperId argument. The attack can be initiated remotely, making it a potential threat. The attack complexity is considered high, and exploitation is known to be difficult but publicly disclosed. Despite early notification, the vendor has not responded to the disclosure.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share