CVE-2025-3388

CVSS 2.0 Score 5 of 10 (medium)

Details

Published Apr 7, 2025
Updated: Apr 8, 2025
CWE ID 94
CWE ID 79

Summary

CVE-2025-3388 is a newly disclosed cross-site scripting (XSS) vulnerability affecting Hailey888's oa_system up to version 2025.01.01. The issue lies within the loginCheck function of the File cn/gson/oasys/controller/login/LoginsController.java, which is part of the Frontend component. The vulnerability can be triggered by manipulating the Username argument, allowing an attacker to inject malicious scripts. This exploit can be executed remotely, posing a significant threat. Despite continuous delivery with rolling releases, no specific version details of the affected or updated releases have been disclosed. Users are advised to apply patches as soon as they become available.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share