CVE-2025-1226
CVSS 3.1 Score 5.3 of 10 (medium)
Details
Published Feb 12, 2025
CWE ID 285
CWE ID 266
Summary
CVE-2025-1226 is a critical vulnerability affecting ywoa up to version 2024.07.03. The issue lies within the unknown code of the file /oa/setup/setup.jsp, leading to improper authorization. The exploit can be initiated remotely and the attacker may gain unauthorized access. The vulnerability has been disclosed to the public, increasing the risk of exploitation. To mitigate this issue, it is strongly recommended to upgrade to the latest version, 2024.07.04.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.