CVE-2025-1225

CVSS 3.1 Score 6.3 of 10 (medium)

Details

Published Feb 12, 2025
CWE ID 611
CWE ID 610

Summary

CVE-2025-1225 is a recently disclosed vulnerability affecting the ywoa software up to version 2024.07.03. The issue lies within the XMLParse.java file, specifically the extract function, of the WXCallBack Interface component. This vulnerability enables an attacker to exploit xml external entity references, potentially leading to remote code execution. The exploit has been made public, increasing the risk for potential attacks. Upgrading to version 2024.07.04 is recommended to mitigate this vulnerability.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share