CVE-2025-25580

CVSS 3.1 Score 6.1 of 10 (medium)

Details

Published Mar 18, 2025
Updated: Mar 19, 2025
CWE ID 89

Summary

CVE-2025-25580 refers to a SQL injection vulnerability identified in the yimioa software before version 2024.07.04. This issue was discovered in the UserMapper.xml file, specifically in the listNameBySql() method. An attacker could exploit this flaw by injecting malicious SQL queries, which could result in unauthorized access to sensitive data or even system takeover. Users are strongly urged to upgrade to a patched version as soon as possible to mitigate the risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share