PT-2025-47086 · Weiye Jing · Datax-Web

Sh7Err

·

Published

2025-11-16

·

Updated

2025-11-20

·

CVE-2025-13250

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions WeiYe-Jing datax-web versions up to 2.1.2
Description A flaw exists in the Job Handler component of WeiYe-Jing datax-web, specifically within the remove, update, pause, start, and triggerJob functions. This issue results in improper access controls, potentially allowing for remote exploitation. The exploit is publicly available.
Recommendations Versions prior to 2.1.2 should be updated. As a temporary workaround, consider disabling the remove, update, pause, start, and triggerJob functions until a patch is available.

Exploit

Fix

Improper Access Control

Incorrect Privilege Assignment

Weakness Enumeration

Related Identifiers

CVE-2025-13250

Affected Products

Datax-Web