CVE-2025-1224
CVSS 3.1 Score 6.3 of 10 (medium)
Details
Published Feb 12, 2025
Updated: Feb 13, 2025
CWE ID 89
CWE ID 74
Summary
CVE-2025-1224 is a critical vulnerability affecting ywoa up to version 2024.07.03. This issue lies in the function listNameBySql of the UserMapper.xml file (com/cloudweb/oa/mapper/xml/UserMapper.xml). An attacker can exploit this SQL injection vulnerability remotely, leading to potential unauthorized data access. The exploit for this vulnerability has been disclosed publicly, increasing the risk for organizations still using the affected version. To mitigate this risk, it is recommended to immediately upgrade to the latest version, 2024.07.04.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share