CVE-2025-25580
CVSS 3.1 Score 6.1 of 10 (medium)
Details
Published Mar 18, 2025
Updated: Mar 19, 2025
CWE ID 89
Summary
CVE-2025-25580 refers to a SQL injection vulnerability identified in the yimioa software before version 2024.07.04. This issue was discovered in the UserMapper.xml file, specifically in the listNameBySql() method. An attacker could exploit this flaw by injecting malicious SQL queries, which could result in unauthorized access to sensitive data or even system takeover. Users are strongly urged to upgrade to a patched version as soon as possible to mitigate the risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.