CVE-2025-15503
Sangfor Operation and Maintenance Management System common.jsp unrestricted upload
Basic Information
- CVE State
- PUBLISHED
- Reserved Date
- January 09, 2026
- Published Date
- January 10, 2026
- Last Updated
- February 23, 2026
- Vendor
- Sangfor
- Product
- Operation and Maintenance Management System
- Description
- A security flaw has been discovered in Sangfor Operation and Maintenance Management System up to 3.0.8. The impacted element is an unknown function of the file /fort/trust/version/common/common.jsp. Performing a manipulation of the argument File results in unrestricted upload. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
- Tags
- Exploitation
- poc
- Automatable
- Yes
- Technical Impact
- partial
- Exploited in the Wild
- Yes (2026-03-25 00:00:00 UTC) Source
nuclei_scanner
CVSS Scores
CVSS v4.0
6.9 - MEDIUM
Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
CVSS v3.1
7.3 - HIGH
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R
CVSS v3.0
7.3 - HIGH
Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R
CVSS v2.0
7.5
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR
SSVC Information
Exploit Status
References
Known Exploited Vulnerability Information
| Source | Added Date |
|---|---|
| The Shadowserver (via CIRCL) | 2026-03-25 00:00:00 UTC |
Scanner Integrations
| Scanner | URL | Date Detected |
|---|---|---|
| Nuclei | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2025/CVE-2025-15503.yaml | 2026-06-01 15:34:40 UTC |
Timeline
-
CVE ID Reserved
-
CVE Published to Public
-
Added to KEVIntel
-
Detected by Nuclei