CVE-2025-5140 Details
Description
A vulnerability classified as critical has been found in Seeyon Zhiyuan OA Web Application System up to 8.1 SP2. This affects the function this.oursNetService.getData of the file com\ours\www\ehr\openPlatform1\open4ClientType\controller\ThirdMenuController.class. The manipulation of the argument url leads to server-side request forgery. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
A critical server-side request forgery (SSRF) vulnerability has been identified in Seeyon Zhiyuan OA Web Application System versions through 8.1 SP2. The issue arises in the ThirdMenuController.class file, specifically within the this.oursNetService.getData function. The vulnerability allows remote attackers to manipulate the url argument, potentially leading to unauthorized network requests that could target internal systems or external networks.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed May 25, 2025CISA-ADP
Assessed May 28, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://vuldb.com/?ctiid.310221 | [email protected] | Content Wall |
| https://vuldb.com/?id.310221 | [email protected] | AdvisoryExploitPartial Content |
| https://vuldb.com/?submit.574440 | [email protected] | Technical Description |
| https://wx.mail.qq.com/s?k=i0-p-2N4MHcFOeM00E | [email protected] | Partial Content |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-918 | Server-Side Request Forgery (SSRF) | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Seeyon Zhiyuan OA Web Application System | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 25, 2025 | New CVE Received | [email protected] |
Volerion