Beveiligingsadvies

CVE-2025-5679

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2025-06-05 19:00:23
Laatst bijgewerkt 2025-06-05 19:14:29
Toegewezen door VulDB
CVSS-score 6.5
Status PUBLISHED

Beschrijving

A vulnerability classified as critical has been found in Shenzhen Dashi Tongzhou Information Technology AgileBPM up to 2.5.0. Affected is the function parseStrByFreeMarker of the file /src/main/java/com/dstz/sys/rest/controller/SysToolsController.java. The manipulation of the argument str leads to deserialization. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.