Improper Authorization Vulnerability in YunaiV yudao-cloud
CVE-2025-10277
5.3MEDIUM
What is CVE-2025-10277?
A vulnerability was identified in YunaiV's yudao-cloud affecting versions up to 2025.09, specifically tied to the file processing at /crm/receivable/submit. This flaw allows for improper authorization due to manipulation of the argument ID, which can be exploited remotely. The issue has been publicly disclosed, and despite attempts to notify the vendor, no response was provided.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
yudao-cloud 2025.09
