Metrics
Affected Vendors & Products
Thu, 05 Jun 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 05 Jun 2025 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability classified as critical was found in Shenzhen Dashi Tongzhou Information Technology AgileBPM up to 2.5.0. Affected by this vulnerability is the function executeScript of the file /src/main/java/com/dstz/sys/rest/controller/SysScriptController.java of the component Groovy Script Handler. The manipulation of the argument script leads to deserialization. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. | |
| Title | Shenzhen Dashi Tongzhou Information Technology AgileBPM Groovy Script SysScriptController.java executeScript deserialization | |
| Weaknesses | CWE-20 CWE-502 |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published: 2025-06-05T19:31:09.376Z
Updated: 2025-06-05T19:53:46.399Z
Reserved: 2025-06-04T13:17:41.924Z
Link: CVE-2025-5680
Updated: 2025-06-05T19:43:34.306Z
Status : Awaiting Analysis
Published: 2025-06-05T20:15:26.790
Modified: 2025-06-06T14:07:28.330
Link: CVE-2025-5680
No data.