VendorsAaluoxiangoa_systemall versions
Vulnerabilities

Aaluoxiang OA System

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

7CVEs
CVE-2025-44033
SQL injection vulnerability in oa_system oasys v.1.1 allows a remote attacker to execute arbitrary code via the allDirector() method declaration in src/main/java/cn/gson/oasys/mappers/AddressMapper.java
Published 2025-08-29 · Analyzed
9.8EPSS 0.006
CVE-2025-1958
aaluoxiang oa_system address-mapper.xml sql injection
Published 2025-03-04 · Analyzed
9.8EPSS 0.005
CVE-2025-6829
aaluoxiang oa_system External Address Book outAddress sql injection
Published 2025-06-28 · Analyzed
8.8EPSS 0.004
CVE-2025-44034
SQL injection vulnerability in oa_system oasys v.1.1 allows a remote attacker to execute arbitrary code via the alph parameters in src/main/Java/cn/gson/oasys/controller/address/AddrController
Published 2025-09-16 · Analyzed
8.0EPSS 0.005
CVE-2025-5544
aaluoxiang oa_system UserpanelController.java image path traversal
Published 2025-06-03 · Analyzed
7.5EPSS 0.007
CVE-2025-5545
aaluoxiang oa_system ProcedureController.java image path traversal
Published 2025-06-03 · Analyzed
7.5EPSS 0.007
CVE-2025-29592
oasys v1.1 is vulnerable to Directory Traversal in ProcedureController.
Published 2025-09-10 · Analyzed
5.6EPSS 0.005