CVE-2025-3389

CVSS 2.0 Score 4 of 10 (medium)

Details

Published Apr 8, 2025
CWE ID 94
CWE ID 79

Summary

CVE-2025-3389 is a newly disclosed vulnerability affecting hailey888 oa_system up to version 2025.01.01. This issue lies in the function testMess of the file InformManageController.java within the Backend component. It permits cross-site scripting attacks, which can be initiated remotely, due to insufficient input validation. The manipulation of the argument menu triggers this vulnerability. Unfortunately, no information is available regarding affected or unaffected releases, as the product does not utilize versioning. This vulnerability has been publicly disclosed and can be exploited by attackers.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share