Template Engine Exploit in zhilink Application Developer Platform
CVE-2025-5325

5.3MEDIUM

What is CVE-2025-5325?

A vulnerability exists in the ADP Application Developer Platform developed by zhilink, related to the improper handling of special elements within its template engine. This flaw is linked to the functionality of the '/adpweb/a/ica/api/service/rfa/testService' file, which can be exploited remotely. The attack allows unauthorized manipulation, potentially leading to unauthorized access and control over the application. Despite early notification of the vulnerability to the vendor, there has been no acknowledgment, leaving the product vulnerable.

Affected Version(s)

ADP Application Developer Platform 应用开发者平台 1.0.0

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Id3al (VulDB User)
.
CVE-2025-5325 : Template Engine Exploit in zhilink Application Developer Platform