Template Engine Exploit in zhilink Application Developer Platform
CVE-2025-5325
What is CVE-2025-5325?
A vulnerability exists in the ADP Application Developer Platform developed by zhilink, related to the improper handling of special elements within its template engine. This flaw is linked to the functionality of the '/adpweb/a/ica/api/service/rfa/testService' file, which can be exploited remotely. The attack allows unauthorized manipulation, potentially leading to unauthorized access and control over the application. Despite early notification of the vulnerability to the vendor, there has been no acknowledgment, leaving the product vulnerable.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
ADP Application Developer Platform 应用开发者平台 1.0.0
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
