MEDIUM🇬🇧 English

CVE-2025-15503

CVSS 5.5v4.0pub. 2026-01-10upd. 2026-04-29

W Sangfor Operation and Maintenance Management System do wersji 3.0.8 odkryto lukę bezpieczeństwa. Podatny element znajduje się w nieznanej funkcji pliku /fort/trust/version/common/common.jsp, gdzie manipulacja parametrem File prowadzi do unrestricted upload. Atak można wykonać zdalnie, exploit został ujawniony publicznie, a producent nie odpowiedział na zawiadomienie.

Pokaż oryginał (EN)

A security flaw has been discovered in Sangfor Operation and Maintenance Management System up to 3.0.8. The impacted element is an unknown function of the file /fort/trust/version/common/common.jsp. Performing a manipulation of the argument File results in unrestricted upload. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Sangfor Operation And Maintenance Security Management System

    APP
    Sangfor
    ≤ 3.0.8
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
CWE
Referencje

Powiązane podatności

CVE-2026-1324HIGH7.4ten sam produkt

A vulnerability was identified in Sangfor Operation and Maintenance Management System up to 3.0.12. Affected b...

CVE-2025-15501HIGH8.9ten sam produkt

A vulnerability was determined in Sangfor Operation and Maintenance Management System up to 3.0.8. Impacted is...

CVE-2026-1412MEDIUM5.5ten sam produkt

W Sangfor Operation and Maintenance Security Management System do wersji 3.0.12 odkryto podatność. Zagrożona j...

CVE-2026-1325MEDIUM5.5ten sam produkt

W systemie Sangfor Operation and Maintenance Security Management System do wersji 3.0.12 odkryto lukę bezpiecz...

CVE-2025-15502MEDIUM5.5ten sam produkt

W Sangfor Operation and Maintenance Management System do wersji 3.0.8 zidentyfikowano podatność. Podatny eleme...