Template Engine Exploit in zhilink Application Developer Platform
CVE-2025-5325
5.3MEDIUM
What is CVE-2025-5325?
A vulnerability exists in the ADP Application Developer Platform developed by zhilink, related to the improper handling of special elements within its template engine. This flaw is linked to the functionality of the '/adpweb/a/ica/api/service/rfa/testService' file, which can be exploited remotely. The attack allows unauthorized manipulation, potentially leading to unauthorized access and control over the application. Despite early notification of the vulnerability to the vendor, there has been no acknowledgment, leaving the product vulnerable.
Affected Version(s)
ADP Application Developer Platform 应用开发者平台 1.0.0