CNNVD-202511-1819 Information

CNNVD ID

CNNVD-202511-1819

CVE-2025-13249

  • CNNVD Published: 2025-11-16

Description (Chinese)

Jiusi OA是中国九思(Jiusi)公司的一个协同办公系统。 Jiusi OA 20251102及之前版本存在代码问题漏洞,该漏洞源于对文件/OfficeServer中参数FileData的错误操作,可能导致无限制上传。

Description (English)

Jiusi OA is a coordinated office system for Jiusi in China. There is a code gap in Jiusi OA 20255102 and previous versions, which stems from an error in the FileData parameter in file/OfficeServer, which may lead to unlimited upload.

Hazard Level

High

Vulnerability Type

代码问题

Affected Vendor

九思

Published

2025-11-16

Last Modified

2026-02-24

References

https://github.com/rooboot501/my-project/blob/main/jiousi.md https://vuldb.com/?submit.687599 https://vuldb.com/?ctiid.332583 https://vuldb.com/?id.332583 https://access.redhat.com/security/cve/cve-2025-13249

Share on: