CVE-2025-14697 is a security flaw in Shenzhen Sixun Software Sixun Shanghui Group Business Management System 4.10.24.3, specifically within an unknown function of the /ExportFiles/ directory, allowing remote access to files or directories. Despite its remote attack vector, the vulnerability has a low CVSS score of 3.7 due to high attack complexity and difficult exploitation, with a potential impact of low confidentiality. An exploit has been publicly released, but there is no evidence of active exploitation, and it has garnered minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Shenzhen Sixun Software | Sixun Shanghui Group Business Management System | 4.10.24.3CNA affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.3 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.