CVE-2025-5545 - CVE House
Back to Database
Status published Medium CVE-2025-5545

aaluoxiang oa_system ProcedureController.java image path traversal

Vulnerability Description

A vulnerability classified as problematic has been found in aaluoxiang oa_system up to 5b445a6227b51cee287bd0c7c33ed94b801a82a5. This affects the function image of the file src/main/java/cn/gson/oasys/controller/process/ProcedureController.java. The manipulation leads to path traversal. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. This product does not use versioning. This is why information about affected and unaffected releases are unavailable.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-5545

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

oa_system
Vulnerable Versions:
5b445a6227b51cee287bd0c7c33ed94b801a82a5

Timeline

Official Publish: June 3rd, 2025
Last Modified: June 4th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Weaknesses (CWE)