Cross site scripting vulnerability in seeyon Zhiyuan A8+ Collaborative Management Software 7.0 via the topValue parameter to the seeyon/main.do endpoint.
References
| Link | Resource |
|---|---|
| https://gist.github.com/076w/b223381ba06b05845d919fb29619777b | Third Party Advisory |
| https://www.yuque.com/076w/syst1m/zlp7c6hmowx6cg51?singleDoc | Exploit |
Configurations
History
05 Feb 2026, 21:49
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:seeyon:a8\+_collaborative_management:7.0:sp3:*:*:*:*:*:* | |
| First Time |
Seeyon a8\+ Collaborative Management
Seeyon |
|
| References | () https://gist.github.com/076w/b223381ba06b05845d919fb29619777b - Third Party Advisory | |
| References | () https://www.yuque.com/076w/syst1m/zlp7c6hmowx6cg51?singleDoc - Exploit |
16 Jan 2026, 22:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-01-16 22:16
Updated : 2026-02-05 21:49
NVD link : CVE-2025-56451
Mitre link : CVE-2025-56451
CVE.ORG link : CVE-2025-56451
JSON object : View
Products Affected
seeyon
- a8\+_collaborative_management
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
