PT-2025-37271 · Yunaiv · Yudao-Cloud
Aibot888
·
Published
2025-09-12
·
Updated
2025-09-12
·
CVE-2025-10275
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
YunaiV yudao-cloud versions prior to 2025.09
Description:
A weakness exists in YunaiV yudao-cloud that may lead to improper authorization. The issue affects an unknown part of the file
/crm/business/transfer. Manipulation of the argument ids/newOwnerUserId can be exploited remotely. The exploit has been made publicly available. The vendor was contacted but did not respond.Recommendations:
Versions prior to 2025.09: Address improper authorization by carefully reviewing and securing the
/crm/business/transfer file and the ids/newOwnerUserId argument.Exploit
Fix
Improper Authorization
Incorrect Privilege Assignment
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Yudao-Cloud