Skip to main content

CVE-2025-11140

7.3
HIGHCVSS v3.1 Base Score
0.05%
LOW RiskEPSS (15th percentile)

A vulnerability was identified in Bjskzy Zhiyou ERP up to 11.0. Affected by this vulnerability is the function openForm of the component com.artery.richclient.RichClientService. Such manipulation of the argument contentString leads to xml external entity reference. The attack can be executed remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.

Published: 9/29/2025
Modified: 10/3/2025
Back to CVE Lookup

Vulnerability Summary

CVSS v3 Score

7.3HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

EPSS Score (Exploitation Probability)

0.05%LOW Exploitation Risk
15th percentile

This vulnerability has a 0.05% probability of being exploited in the next 30 days, ranking higher than 15% of all scored CVEs.

Related Vulnerabilities