CVE-2025-25582
CVSS 3.1 Score 6.1 of 10 (medium)
Details
Published Mar 18, 2025
Updated: Apr 2, 2025
CWE ID 89
Summary
CVE-2025-25582 is a newly identified SQL injection vulnerability affecting yimioa before version 2024.07.04. This issue resides in the selectNoticeList() method located at /xml/OaNoticeMapper.xml. An attacker can exploit this flaw by injecting malicious SQL statements, potentially gaining unauthorized access to sensitive data or taking control of the underlying database. It is strongly recommended that users upgrade to the latest version of yimioa to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.