CVE-2025-3388
CVSS 2.0 Score 5 of 10 (medium)
Details
Summary
CVE-2025-3388 is a newly disclosed cross-site scripting (XSS) vulnerability affecting Hailey888's oa_system up to version 2025.01.01. The issue lies within the loginCheck function of the File cn/gson/oasys/controller/login/LoginsController.java, which is part of the Frontend component. The vulnerability can be triggered by manipulating the Username argument, allowing an attacker to inject malicious scripts. This exploit can be executed remotely, posing a significant threat. Despite continuous delivery with rolling releases, no specific version details of the affected or updated releases have been disclosed. Users are advised to apply patches as soon as they become available.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.