Metrics
Affected Vendors & Products
Wed, 12 Nov 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Tongzhouyun
Tongzhouyun agilebpm |
|
| CPEs | cpe:2.3:a:tongzhouyun:agilebpm:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Tongzhouyun
Tongzhouyun agilebpm |
Thu, 05 Jun 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 05 Jun 2025 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability classified as critical was found in Shenzhen Dashi Tongzhou Information Technology AgileBPM up to 2.5.0. Affected by this vulnerability is the function executeScript of the file /src/main/java/com/dstz/sys/rest/controller/SysScriptController.java of the component Groovy Script Handler. The manipulation of the argument script leads to deserialization. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. | |
| Title | Shenzhen Dashi Tongzhou Information Technology AgileBPM Groovy Script SysScriptController.java executeScript deserialization | |
| Weaknesses | CWE-20 CWE-502 |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2025-06-05T19:53:46.399Z
Reserved: 2025-06-04T13:17:41.924Z
Link: CVE-2025-5680
Updated: 2025-06-05T19:43:34.306Z
Status : Analyzed
Published: 2025-06-05T20:15:26.790
Modified: 2025-11-12T17:07:47.567
Link: CVE-2025-5680
No data.