SQL Injection Vulnerability in Seeyon Zhiyuan OA Web Application System
CVE-2025-15447
Key Information:
- Vendor
Seeyon
- Vendor
- CVE Published:
- 4 January 2026
Badges
What is CVE-2025-15447?
The Seeyon Zhiyuan OA Web Application System is vulnerable to a SQL Injection flaw located in the file /assetsGroupReport/assetsService.j%73p. This vulnerability allows attackers to manipulate the 'unitCode' parameter, enabling the execution of arbitrary SQL queries on the database. Attackers could exploit this remotely, posing significant risks to data integrity and security. Despite early notifications to the vendor regarding this issue, there has been no response or patch provided, highlighting a critical lapse in addressing security vulnerabilities.
Affected Version(s)
Zhiyuan OA Web Application System 20251223
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
