Vendorshailey888oa_systemany version
Vulnerabilities

hailey888 Oa System any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

10CVEs
CVE-2025-3388
hailey888 oa_system Frontend LoginsController.java loginCheck cross site scripting
Published 2025-04-07 · Analyzed
6.1EPSS 0.004
CVE-2025-3391
hailey888 oa_system Backend AddrController. java outAddress cross site scripting
Published 2025-04-08 · Analyzed
6.1EPSS 0.003
CVE-2025-3389
hailey888 oa_system Backend InformManageController.java testMess cross site scripting
Published 2025-04-07 · Analyzed
6.1EPSS 0.003
CVE-2025-3390
hailey888 oa_system Backend DaymanageController.java addandchangeday cross site scripting
Published 2025-04-08 · Analyzed
6.1EPSS 0.003
CVE-2025-3392
hailey888 oa_system Backend MailController.java save cross site scripting
Published 2025-04-08 · Analyzed
6.1EPSS 0.003
CVE-2025-29686
A cross-site scripting (XSS) vulnerability in OA System before v2025.01.01 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the title parameter at /inform/InformManageController.java.
Published 2025-05-14 · Analyzed
6.1EPSS 0.003
CVE-2025-29688
A cross-site scripting (XSS) vulnerability in OA System before v2025.01.01 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the title parameter at /daymanager/daymanageabilitycontroller.java.
Published 2025-05-14 · Analyzed
6.1EPSS 0.003
CVE-2025-29689
A cross-site scripting (XSS) vulnerability in OA System before v2025.01.01 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the password parameter at /mail/MailController.java.
Published 2025-05-14 · Analyzed
6.1EPSS 0.003
CVE-2025-29690
A cross-site scripting (XSS) vulnerability in OA System before v2025.01.01 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the outtype parameter at /address/AddrController.java.
Published 2025-05-14 · Analyzed
6.1EPSS 0.003
CVE-2025-29691
A cross-site scripting (XSS) vulnerability in OA System before v2025.01.01 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the userName parameter at /login/LoginsController.java.
Published 2025-05-14 · Analyzed
6.1EPSS 0.003