---
id: CVE-2025-13209
title: A weakness has been identified in bestfeng oa_git_free up to 9.5
summary: >-
  A weakness has been identified in bestfeng oa_git_free up to 9.5. This affects
  the function updateWriteBack of the file
  yimioa-oa9.5\server\c-flow\src\main\java\com\cloudweb\oa\controller\WorkflowPredefineController.java.
  This manipulati…
severity: medium
cvss: 6.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L'
cwe:
  - CWE-610
  - CWE-611
published: '2025-11-15'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T21:10:00.200'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-13209'
references:
  - url: >-
      https://github.com/bkglfpp/CVE-md/blob/main/%E4%BA%91%E7%BD%91%E5%8D%8F%E5%90%8C%E5%8A%9E%E5%85%AC%E7%B3%BB%E7%BB%9F/XXE.md
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?ctiid.332528'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?id.332528'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?submit.685626'
    label: cna@vuldb.com
tags:
  - nvd
epss: 0.00291
epssPercentile: 0.19846
ingestedAt: '2026-10-07T21:54:15.047Z'
---

## Overview

A weakness has been identified in bestfeng oa_git_free up to 9.5. This affects the function updateWriteBack of the file yimioa-oa9.5\server\c-flow\src\main\java\com\cloudweb\oa\controller\WorkflowPredefineController.java. This manipulation of the argument writeProp causes xml external entity reference. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be exploited.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
