← back
CVE-2025-4281mediumobserved exploitationCWE-200CWE-284

Shenzhen Sixun Software Sixun Shanghui Group Business Management System LoadData information disclosure

35Vexday Risk Score

Prioritize patching. It exploitation observed by VulnCheck.

ssvc Attendcvss 5.3epss 0.3%
from disclosure to weapon
Published on NVDMay 5
VulnCheck+77d
exploitation probability
0.3%top 78% of all CVEs
observed exploitation
yesVulnCheck
A vulnerability, which was classified as problematic, was found in Shenzhen Sixun Software Sixun Shanghui Group Business Management System 7. This affects an unknown part of the file /api/GylOperator/LoadData. The manipulation leads to information disclosure. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N