CVE-2025-23944
CVSS 3.1 Score 8.8 of 10 (high)
Details
Published Jan 22, 2025
CWE ID 502
Summary
CVE-2025-23944 is a Deserialization of Untrusted Data vulnerability affecting the WOOEXIM platform, from an unknown version up to 5.0.0. The issue enables Object Injection, making it possible for attackers to execute arbitrary code on the system by providing malicious data during the deserialization process. Successful exploitation could lead to unauthorized access, data theft, or system compromise. Users are strongly encouraged to apply the necessary patches or updates to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.