CVE-2025-25589

CVSS 3.1 Score 8.1 of 10 (high)

Details

Published Mar 18, 2025
Updated: Mar 21, 2025
CWE ID 91

Summary

CVE-2025-25589 is an XML external entity (XXE) injection vulnerability affecting the component /weixin/aes/XMLParse.java in yimioa before version 2024.07.04. This vulnerability enables attackers to execute arbitrary code by supplying a maliciously crafted XML file. Attackers can exploit this weakness to launch serious attacks, potentially leading to data theft, system compromise, or other malicious activities. XML Parse.java fails to properly validate and sanitize XML input, allowing attackers to inject and manipulate external entities. It is essential for users to upgrade to the latest version of yimioa to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share