A vulnerability, which was classified as problematic, has been found in Fengoffice Feng Office 3.2.2.1. Affected by this issue is some unknown functionality of the file /application/models/ApplicationDataObject.class.php of the component Document Upload Handler. The manipulation leads to xml external entity reference. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
History

Wed, 02 Jul 2025 19:45:00 +0000

Type Values Removed Values Added
First Time appeared Fengoffice
Fengoffice feng Office
CPEs cpe:2.3:a:fengoffice:feng_office:3.2.2.1:*:*:*:*:*:*:*
Vendors & Products Fengoffice
Fengoffice feng Office

Mon, 09 Jun 2025 13:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 09 Jun 2025 12:45:00 +0000

Type Values Removed Values Added
Description A vulnerability, which was classified as problematic, has been found in Fengoffice Feng Office 3.2.2.1. Affected by this issue is some unknown functionality of the file /application/models/ApplicationDataObject.class.php of the component Document Upload Handler. The manipulation leads to xml external entity reference. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Title Fengoffice Feng Office Document Upload ApplicationDataObject.class.php xml external entity reference
Weaknesses CWE-610
CWE-611
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published: 2025-06-09T12:31:04.643Z

Updated: 2025-06-09T13:00:44.810Z

Reserved: 2025-06-08T18:05:09.822Z

Link: CVE-2025-5877

cve-icon Vulnrichment

Updated: 2025-06-09T13:00:34.730Z

cve-icon NVD

Status : Analyzed

Published: 2025-06-09T13:15:26.017

Modified: 2025-07-02T19:17:43.003

Link: CVE-2025-5877

cve-icon Redhat

No data.