CVE-2025-3391

CVSS 2.0 Score 4 of 10 (medium)

Details

Published Apr 8, 2025
CWE ID 94
CWE ID 79

Summary

CVE-2025-3391 is a recently disclosed vulnerability affecting hailey888 oa_system up to version 2025.01.01. This issue is classified as problematic and involves the outAddress function in the file cn/gson/oass/controller/address/AddrController.java within the Backend component. Manipulation of the outtype argument can lead to cross-site scripting attacks, which can be executed remotely. Due to the product's rolling release approach for continuous delivery, specific version details for affected and updated releases have not been made available. However, it is important to note that the exploit for this vulnerability has been disclosed to the public.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share