PT-2025-19727 · Shenzhen Sixun · Sixun Shanghui Group Business Management System

Yaozhangyiqiyin

·

Published

2025-05-05

·

Updated

2025-05-05

·

CVE-2025-4281

CVSS v2.0

4.0

Medium

VectorAV:N/AC:L/Au:S/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Shenzhen Sixun Software Sixun Shanghui Group Business Management System version 7
Description A vulnerability was found in the system, affecting an unknown part of the file "/api/GylOperator/LoadData". The manipulation leads to information disclosure and can be initiated remotely. The exploit has been disclosed to the public and may be used.
Recommendations For Shenzhen Sixun Software Sixun Shanghui Group Business Management System version 7, as a temporary workaround, consider restricting access to the "/api/GylOperator/LoadData" endpoint until a patch is available. Avoid using this endpoint remotely to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Access Control

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2025-4281

Affected Products

Sixun Shanghui Group Business Management System