github.comexploitissue tracking
https://github.com/zhangbuneng/an-unauthorized-vulnerability-in-the-business-management-system-of-Wisdom-7-Group/issues/1 CVE-2025-4281
MEDIUM
Shenzhen Sixun Software Sixun Shanghui Group Business Management System LoadData information disclosure
Record summary
CVE-2025-4281 has a selected CVSS score of 5.3 (medium).
Description
A vulnerability, which was classified as problematic, was found in Shenzhen Sixun Software Sixun Shanghui Group Business Management System 7. This affects an unknown part of the file /api/GylOperator/LoadData. The manipulation leads to information disclosure. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Jul 21, 2025 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated May 5, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Sixun Shanghui Group Business Management SystemBrowse Shenzhen Sixun Software / Sixun Shanghui Group Business Management System | CVE List, VulnCheck | 7 | affected |
References
5nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2025-4281 VDB-307389 | CTI Indicators (IOB, IOC, TTP, IOA)signaturepermissions required
https://vuldb.com/?ctiid.307389 VDB-307389 | Shenzhen Sixun Software Sixun Shanghui Group Business Management System LoadData information disclosurevdb entry
https://vuldb.com/?id.307389 Submit #563515 | Shenzhen Sixun Software Co., Ltd Sixun Shanghui 7 Group Business Management System 7 Unauthorized information disclosureThird-party advisory
https://vuldb.com/?submit.563515