CVE-2025-3390 | hailey888 oa_system up to 2025.01.01 Backend DaymanageController.java addandchangeday scheduleList cross site scripting (IBRRZX)
A vulnerability, which was classified as problematic, was found in hailey888 oa_system up to 2025.01.01. Affected is the function addandchangeday of the file cn/gson/oass/controller/daymanager/DaymanageController.java of the component Backend. The manipulation of the argument scheduleList leads to cross site scripting.
This vulnerability is traded as CVE-2025-3390. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available.