CNNVD-202512-2078 Information

CNNVD ID

CNNVD-202512-2078

CVE-2025-14538

  • CNNVD Published: 2025-12-11

Description (Chinese)

warehouseManager是中国yangshare个人开发者的一个仓库管理系统。 warehouseManager 1.1.0版本存在代码注入漏洞,该漏洞源于文件CustomerManageHandler.java中函数addCustomer对参数Name的错误操作,可能导致跨站脚本攻击。

Description (English)

WarehouseManager is a warehouse management system for Yangshare personal developers in China. There is a code-injection loophole in version 1.1.0 of the warehouseManager, which results from the error of the ddCustomer function in document CustomerManagehandler.java against the parameter name, which may result in a cross-script attack.

Hazard Level

Critical

Vulnerability Type

代码注入

Affected Vendor

个人开发者

Published

2025-12-11

Last Modified

2026-02-24

References

https://gitee.com/yangshare/warehouseManager/issues/ID9NAU https://vuldb.com/?ctiid.335877 https://vuldb.com/?id.335877 https://vuldb.com/?submit.703736

Share on: