CVE-2025-2365
CVSS 3.1 Score 7.1 of 10 (high)
Details
Published Mar 17, 2025
CWE ID 79
Summary
CVE-2025-2365 is a recently disclosed vulnerability affecting crmeb_java versions up to 1.3.4. The issue lies in the webHook function of WeChatMessageController.java, which can be exploited through xml external entity references. This manipulation allows an attacker to launch a remote attack, making it a potential security risk. The exploit for this vulnerability has been made public, increasing the likelihood of it being used in malicious activities.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.