References https://nvd.nist.gov/vuln/detail/CVE-2025-21015 https://cve.imfht.com/detail/CVE-2025-21015?lang=en https://www.cve.org/CVERecord?id=CVE-2025-21015 https://strobes.co/vi/cve/CVE-2025-21015/ https://security.samsungmobile.com/securityUpdate.smsb?year=2025&month=04 https://github.com/advisories/GHSA-c5jw-r9jr-pf7j https://cve.imfht.com/detail/CVE-2025-21015 https://www.tenable.com/cve/CVE-2025-21015
Related VulnerabilitiesPoCCVE-2026-87820: CyberPanel 2.4.3-2.4.5 - AI Scanner Debug Disclosure广联达OA /GB/LK/Document/DataExchange/DataExchange.ashx XML 外部实体注入漏洞致远互联FE协作办公平台 /document/file_publish_open.jsp SQL 注入漏洞PoCCAREL Boss Mini /boss/servlet/document 文件包含漏洞(CVE-2023-3643)天锐绿盘云文档安全管理平台/lddsm/service/../ldfbsnodeDocumentController/restorMachineToClient.do 命令执行漏洞必智律师事务所综合管理系统document.asp 存在SQL注入漏洞PoCCVE-2025-5301: ONLYOFFICE Docs (DocumentServer) - Reflected Cross-Site Scripting万户OA /defaultroot/modules/govoffice/gov_documentmanager/govdocumentmanager_sendfile_gd.jsp;.js SQL 注入漏洞PoC万户ezOFFICE协同管理平台 /defaultroot/modules/govoffice/gov_documentmanager/receivefile_gd.jsp;.js SQL 注入漏洞昂捷CRM GetDocumentNoByGuid SQL注入漏洞昂捷CRM GetDocumentList SQL注入漏洞