CVE 5.3 MEDIUM

Jiusi OA OfficeServer unrestricted upload_CVE-2025-13249

5.3 / 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P

Description

A security vulnerability has been detected in Jiusi OA up to 20251102. This affects an unknown function of the file /OfficeServer?isAjaxDownloadTemplate=false of the component OfficeServer Interface. Such manipulation of the argument FileData leads to unrestricted upload. The attack can be launched remotely. The exploit has been disclosed publicly and may be used.

Basic Information

ID CVE-2025-13249
Source VulDB
Published Nov 16, 2025 at 11:32

Affected Product

Vendor Jiusi
Product OA
Version 20251102
Affected Versions Jiusi OA 20251102

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.