Aaluoxiang

Oa System

7 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.18%
  • Veröffentlicht 16.09.2025 00:00:00
  • Zuletzt bearbeitet 19.11.2025 17:06:31

SQL injection vulnerability in oa_system oasys v.1.1 allows a remote attacker to execute arbitrary code via the alph parameters in src/main/Java/cn/gson/oasys/controller/address/AddrController

Exploit
  • EPSS 0.21%
  • Veröffentlicht 10.09.2025 00:00:00
  • Zuletzt bearbeitet 19.11.2025 17:06:38

oasys v1.1 is vulnerable to Directory Traversal in ProcedureController.

Exploit
  • EPSS 0.3%
  • Veröffentlicht 29.08.2025 00:00:00
  • Zuletzt bearbeitet 19.11.2025 17:06:22

SQL injection vulnerability in oa_system oasys v.1.1 allows a remote attacker to execute arbitrary code via the allDirector() method declaration in src/main/java/cn/gson/oasys/mappers/AddressMapper.java

Exploit
  • EPSS 0.04%
  • Veröffentlicht 28.06.2025 23:00:12
  • Zuletzt bearbeitet 08.07.2025 14:41:05

A vulnerability was found in aaluoxiang oa_system up to c3a08168c144f27256a90838492c713f55f1b207 and classified as critical. This issue affects the function outAddress of the component External Address Book Handler. The manipulation leads to sql inje...

Exploit
  • EPSS 0.13%
  • Veröffentlicht 03.06.2025 23:31:05
  • Zuletzt bearbeitet 09.06.2025 15:04:45

A vulnerability classified as problematic has been found in aaluoxiang oa_system up to 5b445a6227b51cee287bd0c7c33ed94b801a82a5. This affects the function image of the file src/main/java/cn/gson/oasys/controller/process/ProcedureController.java. The ...

Exploit
  • EPSS 0.1%
  • Veröffentlicht 03.06.2025 23:00:21
  • Zuletzt bearbeitet 15.10.2025 18:08:19

A vulnerability was found in aaluoxiang oa_system up to 5b445a6227b51cee287bd0c7c33ed94b801a82a5. It has been rated as problematic. Affected by this issue is the function image of the file src/main/java/cn/gson/oasys/controller/user/UserpanelControll...

Exploit
  • EPSS 0.1%
  • Veröffentlicht 04.03.2025 22:15:40
  • Zuletzt bearbeitet 15.10.2025 20:49:34

A vulnerability, which was classified as critical, has been found in aaluoxiang oa_system 1.0. This issue affects some unknown processing of the file src/main/resources/mappers/address-mapper.xml. The manipulation of the argument outtype leads to sql...