Home

Description

A weakness has been identified in zhujunliang3 work_platform up to 6bc5a50bb527ce27f7906d11ea6ec139beb79c31. This vulnerability affects unknown code of the component Content Handler. Executing manipulation can lead to cross site scripting. The attack may be performed from remote. This product utilizes a rolling release system for continuous delivery, and as such, version information for affected or updated releases is not disclosed. The project was informed of the problem early through an issue report but has not responded yet.

PUBLISHED Reserved 2025-12-29 | Published 2025-12-30 | Updated 2025-12-30 | Assigner VulDB




MEDIUM: 5.1CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X
LOW: 3.5CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N/E:X/RL:X/RC:R
LOW: 3.5CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N/E:X/RL:X/RC:R
4.0AV:N/AC:L/Au:S/C:N/I:P/A:N/E:ND/RL:ND/RC:UR

Problem types

Cross Site Scripting

Code Injection

Product status

6bc5a50bb527ce27f7906d11ea6ec139beb79c31
affected

Timeline

2025-12-29:Advisory disclosed
2025-12-29:VulDB entry created
2025-12-29:VulDB entry last update

Credits

VulDB Gitee Analyzer tool

References

vuldb.com/?id.338639 (VDB-338639 | zhujunliang3 work_platform Content cross site scripting) vdb-entry

vuldb.com/?ctiid.338639 (VDB-338639 | CTI Indicators (IOB, IOC, TTP)) signature permissions-required

gitee.com/zhujunliang3/work_platform/issues/ICLUJ2 issue-tracking

cve.org (CVE-2025-15249)

nvd.nist.gov (CVE-2025-15249)

Download JSON

Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.