Metrics
Affected Vendors & Products
Fri, 09 Jan 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 09 Jan 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability has been found in Sangfor Operation and Maintenance Management System up to 3.0.8. This vulnerability affects the function uploadCN of the file VersionController.java. The manipulation of the argument filename leads to os command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. | |
| Title | Sangfor Operation and Maintenance Management System VersionController.java uploadCN os command injection | |
| Weaknesses | CWE-77 CWE-78 |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-01-09T21:54:02.443Z
Reserved: 2026-01-09T17:11:56.758Z
Link: CVE-2025-15499
Updated: 2026-01-09T21:52:10.296Z
Status : Received
Published: 2026-01-09T22:15:58.973
Modified: 2026-01-09T22:15:58.973
Link: CVE-2025-15499
No data.
OpenCVE Enrichment
No data.