CVE-2025-5545 | aaluoxiang oa_system up to 5b445a6227b51cee287bd0c7c33ed94b801a82a5 ProcedureController.java image path traversal (EUVD-2025-16798)
A vulnerability classified as problematic has been found in aaluoxiang oa_system up to 5b445a6227b51cee287bd0c7c33ed94b801a82a5. This affects the function image of the file src/main/java/cn/gson/oasys/controller/process/ProcedureController.java. The manipulation leads to path traversal.
This vulnerability is uniquely identified as CVE-2025-5545. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
This product does not use versioning. This is why information about affected and unaffected releases are unavailable.