CVE-2025-3402

CVSS 3.1 Score 10 of 10 (high)

Details

Published Apr 8, 2025
Updated: Apr 22, 2025
CWE ID 22

Summary

CVE-2025-3402 is a critical vulnerability affecting Seeyon Zhiyuan Interconnect FE Collaborative Office Platform version 5.5.2. This issue involves the processing of the file /sysform/042/check.js%70, where manipulation of the 'Name' argument allows for SQL injection. An attacker can exploit this remotely, making it a significant risk. The exploit has been disclosed publicly, increasing the threat level. Despite early notification, the vendor has yet to respond to this disclosure.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Command Center Innovation

Affected Vendors

  • CommVault