CVE-2025-3388Disclosure(hailey888 / oa_system)

LOWCVSS 6.1 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability classified as problematic was found in hailey888 oa_system up to 2025.01.01. This vulnerability affects the function loginCheck of the file cn/gson/oasys/controller/login/LoginsController.java of the component Frontend. The manipulation of the argument Username leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available.

0.0/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-79CWE-94

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • oa_system

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
oa_system

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-06-26: 1Technical Details · 2026-06-26: 106-26
Signal classification1 categories
Disclosure
1100.0%
Full discourse1 post
  • CyDhaal@CyberDhaal
    Disclosure

    2/3 Technical overview: • CVE-2025-3388: Use-after-free in V8 exploitable via malicious JavaScript • CVE-2025-3389: Use-after-free in Dawn (WebGPU) triggered through crafted WebGPU calls • CVE-2025-3390: Use-after-free in DevTools requires social engineering These memory corruption flaws can allow attackers to bypass browser sandbox protections and execute arbitrary code on victim machines.

    Post summary

    The text discloses details of three browser memory‑corruption vulnerabilities, explaining their triggers and potential impact on sandbox security, but it does not provide PoC, exploit code, or evidence of active exploitation.

    1000054
    503 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apphailey888oa_system---

Explore more