R1bbit

Yimioa

10 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.03%
  • Veröffentlicht 18.03.2025 00:00:00
  • Zuletzt bearbeitet 19.06.2025 00:18:57

yimioa before v2024.07.04 was discovered to contain a SQL injection vulnerability via the listNameBySql() method at /xml/UserMapper.xml.

Exploit
  • EPSS 0.03%
  • Veröffentlicht 18.03.2025 00:00:00
  • Zuletzt bearbeitet 19.06.2025 00:16:52

Incorrect access control in the component /config/WebSecurityConfig.java of yimioa before v2024.07.04 allows unauthorized attackers to arbitrarily modify Administrator passwords.

Exploit
  • EPSS 0.03%
  • Veröffentlicht 18.03.2025 00:00:00
  • Zuletzt bearbeitet 19.06.2025 00:17:23

yimioa before v2024.07.04 was discovered to contain a SQL injection vulnerability via the component /mapper/xml/AddressDao.xml.

Exploit
  • EPSS 0.03%
  • Veröffentlicht 18.03.2025 00:00:00
  • Zuletzt bearbeitet 02.04.2025 12:27:19

yimioa before v2024.07.04 was discovered to contain a SQL injection vulnerability via the selectNoticeList() method at /xml/OaNoticeMapper.xml.

Exploit
  • EPSS 0.03%
  • Veröffentlicht 18.03.2025 00:00:00
  • Zuletzt bearbeitet 01.04.2025 20:38:38

yimioa before v2024.07.04 was discovered to contain an information disclosure vulnerability via the component /resources/application.yml.

Exploit
  • EPSS 0.1%
  • Veröffentlicht 12.02.2025 21:15:20
  • Zuletzt bearbeitet 26.08.2025 18:38:12

A vulnerability was found in ywoa up to 2024.07.03. It has been declared as critical. This vulnerability affects unknown code of the file /oa/setup/setup.jsp. The manipulation leads to improper authorization. The attack can be initiated remotely. The...

Exploit
  • EPSS 0.08%
  • Veröffentlicht 12.02.2025 21:15:20
  • Zuletzt bearbeitet 26.08.2025 18:39:13

A vulnerability was found in ywoa up to 2024.07.03. It has been rated as critical. This issue affects the function selectList of the file com/cloudweb/oa/mapper/xml/AddressDao.xml. The manipulation leads to sql injection. The attack may be initiated ...

Exploit
  • EPSS 0.08%
  • Veröffentlicht 12.02.2025 20:15:40
  • Zuletzt bearbeitet 26.08.2025 18:37:51

A vulnerability classified as critical was found in ywoa up to 2024.07.03. This vulnerability affects the function listNameBySql of the file com/cloudweb/oa/mapper/xml/UserMapper.xml. The manipulation leads to sql injection. The attack can be initiat...

Exploit
  • EPSS 0.11%
  • Veröffentlicht 12.02.2025 20:15:40
  • Zuletzt bearbeitet 26.08.2025 18:39:03

A vulnerability, which was classified as problematic, has been found in ywoa up to 2024.07.03. This issue affects the function extract of the file c-main/src/main/java/com/redmoon/weixin/aes/XMLParse.java of the component WXCallBack Interface. The ma...

Exploit
  • EPSS 0.1%
  • Veröffentlicht 12.02.2025 19:15:10
  • Zuletzt bearbeitet 26.08.2025 18:38:22

A vulnerability, which was classified as critical, has been found in ywoa up to 2024.07.03. This issue affects the function selectNoticeList of the file com/cloudweb/oa/mapper/xml/OaNoticeMapper.xml. The manipulation of the argument sort leads to sql...