CVE-2025-15447 Details
Description
Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: The vendor mentioned in the original disclosure filed a report that this issue affects a different vendor. The researcher was not able to provide a proof for his disputed claim which is why the CNA decided to revoke the whole entry.
A SQL injection vulnerability has been identified in the Seeyon Zhiyuan OA Web Application System, specifically in versions prior to 20251223. The issue resides in the file '/assetsGroupReport/assetsService.j%73p', where the 'unitCode' parameter can be manipulated to inject malicious SQL queries. This vulnerability can be exploited remotely without authentication, allowing attackers to interfere with database operations and potentially access or modify sensitive information.
It is recommended to use prepared statements and parameter binding to prevent SQL injection, validate and filter user input, minimize database user permissions, and conduct regular security audits.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No CVSS 3.x data is available for this CVE.
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
No references are available for this CVE.
Weakness Enumeration
No weakness enumeration is available for this CVE.
Affected Products
No affected product data is available for this CVE.
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Feb 2, 2026 | CVE Rejected | [email protected] |
| Feb 2, 2026 | CVE Modified | [email protected] |
| Jan 29, 2026 | CVE Modified | [email protected] |
| Jan 20, 2026 | Initial Analysis | [email protected] |
| Jan 5, 2026 | CVE Modified | CISA-ADP |
| Jan 5, 2026 | New CVE Received | [email protected] |