Home

Description

EN DE

A weakness has been identified in bestfeng oa_git_free up to 9.5. This affects the function updateWriteBack of the file yimioa-oa9.5\server\c-flow\src\main\java\com\cloudweb\oa\controller\WorkflowPredefineController.java. This manipulation of the argument writeProp causes xml external entity reference. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be exploited.

Eine Schwachstelle wurde in bestfeng oa_git_free up to 9.5 gefunden. Hierbei geht es um die Funktion updateWriteBack der Datei yimioa-oa9.5\server\c-flow\src\main\java\com\cloudweb\oa\controller\WorkflowPredefineController.java. Dank der Manipulation des Arguments writeProp mit unbekannten Daten kann eine xml external entity reference-Schwachstelle ausgenutzt werden. Die Umsetzung des Angriffs kann dabei über das Netzwerk erfolgen. Der Exploit ist öffentlich verfügbar und könnte genutzt werden.

PUBLISHED Reserved 2025-11-14 | Published 2025-11-15 | Updated 2025-11-17 | Assigner VulDB




MEDIUM: 5.3CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
MEDIUM: 6.3CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R
MEDIUM: 6.3CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R
6.5AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR

Problem types

XML External Entity Reference

Externally Controlled Reference

Product status

9.0
affected

9.1
affected

9.2
affected

9.3
affected

9.4
affected

9.5
affected

Timeline

2025-11-14:Advisory disclosed
2025-11-14:VulDB entry created
2025-11-14:VulDB entry last update

Credits

youran (VulDB User) reporter

References

vuldb.com/?id.332528 (VDB-332528 | bestfeng oa_git_free WorkflowPredefineController.java updateWriteBack xml external entity reference) vdb-entry technical-description

vuldb.com/?ctiid.332528 (VDB-332528 | CTI Indicators (IOB, IOC, IOA)) signature permissions-required

vuldb.com/?submit.685626 (Submit #685626 | https://gitee.com/bestfeng/oa_git_free oa_git_free 8.0 XML external entity injection) third-party-advisory

github.com/...E-md/blob/main/云网协同办公系统/XXE.md exploit

cve.org (CVE-2025-13209)

nvd.nist.gov (CVE-2025-13209)

Download JSON