PT-2025-15307 · Unknown · Hailey888 Oa System

Hailey

·

Published

2025-04-07

·

Updated

2025-05-07

·

CVE-2025-3388

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions hailey888 oa system up to 2025.01.01
Description A vulnerability was found in hailey888 oa system, affecting the function loginCheck of the file cn/gson/oasys/controller/login/LoginsController.java of the component Frontend. The manipulation of the argument Username leads to cross-site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. This product uses continuous delivery with rolling releases, so no version details of affected or updated releases are available.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability. As a temporary workaround, consider restricting the use of the loginCheck function or the Username argument in the affected component to minimize the risk of exploitation.

Exploit

XSS

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2025-3388

Affected Products

Hailey888 Oa System