Metrics
Affected Vendors & Products
Mon, 15 Dec 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 15 Dec 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Shenzhen Sixun
Shenzhen Sixun business Management System |
|
| Vendors & Products |
Shenzhen Sixun
Shenzhen Sixun business Management System |
Mon, 15 Dec 2025 02:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was identified in Shenzhen Sixun Software Sixun Shanghui Group Business Management System 4.10.24.3. Affected by this vulnerability is an unknown functionality of the file /api/GylOperator/UpdatePasswordBatch. The manipulation leads to weak password recovery. The attack may be initiated remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way. | |
| Title | Shenzhen Sixun Software Sixun Shanghui Group Business Management System UpdatePasswordBatch password recovery | |
| Weaknesses | CWE-640 | |
| References |
|
|
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2025-12-15T19:32:29.390Z
Reserved: 2025-12-14T12:22:49.117Z
Link: CVE-2025-14696
Updated: 2025-12-15T19:32:16.905Z
Status : Awaiting Analysis
Published: 2025-12-15T02:15:36.320
Modified: 2025-12-15T18:22:13.783
Link: CVE-2025-14696
No data.