PT-2025-37279 · Yunaiv · Yudao-Cloud

Aibot888

·

Published

2025-09-12

·

Updated

2025-09-12

·

CVE-2025-10277

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: YunaiV yudao-cloud versions prior to 2025.09
Description: A vulnerability exists in YunaiV yudao-cloud that affects processing of the file /crm/receivable/submit. Manipulation of the ID argument results in improper authorization, and the attack can be executed remotely. The exploit is publicly available. The vendor was contacted but did not respond.
Recommendations: Versions prior to 2025.09: Address improper authorization related to the manipulation of the ID argument in the /crm/receivable/submit file processing.

Exploit

Fix

Improper Authorization

Incorrect Privilege Assignment

Weakness Enumeration

Related Identifiers

CVE-2025-10277

Affected Products

Yudao-Cloud