---
id: CVE-2025-14696
title: >-
  A vulnerability was identified in Shenzhen Sixun Software Sixun Shanghui Group
  Business Management System 4.10.24.3
summary: >-
  A vulnerability was identified in Shenzhen Sixun Software Sixun Shanghui Group
  Business Management System 4.10.24.3. Affected by this vulnerability is an
  unknown functionality of the file /api/GylOperator/UpdatePasswordBatch. The
  manipul…
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'
cwe:
  - CWE-640
published: '2025-12-15'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T23:10:00.237'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-14696'
references:
  - url: >-
      https://github.com/zhangbuneng/Sissyun-Shanghui-7-Unauthorized-password-modificationfication-vulnerability./issues/1
    label: cna@vuldb.com
  - url: >-
      https://github.com/zhangbuneng/Sissyun-Shanghui-7-Unauthorized-password-modificationfication-vulnerability./issues/1#issue-3688839620
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?ctiid.336414'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?id.336414'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?submit.705601'
    label: cna@vuldb.com
tags:
  - nvd
epss: 0.00327
epssPercentile: 0.23445
ingestedAt: '2026-09-30T23:29:32.491Z'
---

## Overview

A vulnerability was identified in Shenzhen Sixun Software Sixun Shanghui Group Business Management System 4.10.24.3. Affected by this vulnerability is an unknown functionality of the file /api/GylOperator/UpdatePasswordBatch. The manipulation leads to weak password recovery. The attack may be initiated remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
