CVE-2025-25036
CVSS 3.1 Score 6.8 of 10 (medium)
Details
Published Mar 21, 2025
CWE ID 611
Summary
CVE-2025-25036 is an XML External Entity (XXE) injection vulnerability affecting Jalios JPlatform. The issue, present in all versions of JPlatform 10 before 10.0.8 (SP8), allows unauthorized XML code injection, potentially leading to sensitive information disclosure or server-side request forgery. This vulnerability occurs due to insufficient restrictions on XML external entities. Users are encouraged to upgrade to a secure version as soon as possible to mitigate the risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.