CVE-2025-3391
CVSS 2.0 Score 4 of 10 (medium)
Details
Summary
CVE-2025-3391 is a recently disclosed vulnerability affecting hailey888 oa_system up to version 2025.01.01. This issue is classified as problematic and involves the outAddress function in the file cn/gson/oass/controller/address/AddrController.java within the Backend component. Manipulation of the outtype argument can lead to cross-site scripting attacks, which can be executed remotely. Due to the product's rolling release approach for continuous delivery, specific version details for affected and updated releases have not been made available. However, it is important to note that the exploit for this vulnerability has been disclosed to the public.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.