CVE-2025-10394
A vulnerability has been found in fcba_zzm ics-park Smart Park Management System 2.0. Affected is an unknown function of the file ruoyi-quartz/src/main/java/com/ruoyi/quartz/controller/JobController.java of the component Scheduled Task Module. Such manipulation leads to code injection. The attack may be performed from remote. The exploit has been disclosed to the public and may be used. Es wurde eine Schwachstelle in fcba_zzm ics-park Smart Park Management System 2.0 entdeckt. Betroffen hiervon ist ein unbekannter Ablauf der Datei ruoyi-quartz/src/main/java/com/ruoyi/quartz/controller/JobController.java der Komponente Scheduled Task Module. Durch das Beeinflussen mit unbekannten Daten kann eine code injection-Schwachstelle ausgenutzt werden. Der Angriff kann remote ausgeführt werden. Die Ausnutzung wurde veröffentlicht und kann verwendet werden.
- CVSS v4.0
- 2.0 LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X - CVSS v3.1
- 7.2 HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H - CVSS v3.1
- 4.7 MEDIUM
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L - CVSS v2.0
- 5.8 MEDIUM
AV:N/AC:L/Au:M/C:P/I:P/A:P - EPSS
- 0.43% chance of exploitation in the next 30 days, 36th percentile
- Published
- 2025-09-14
- Updated
- 2025-09-15