CVE-2025-25589
CVSS 3.1 Score 8.1 of 10 (high)
Details
Summary
CVE-2025-25589 is an XML external entity (XXE) injection vulnerability affecting the component /weixin/aes/XMLParse.java in yimioa before version 2024.07.04. This vulnerability enables attackers to execute arbitrary code by supplying a maliciously crafted XML file. Attackers can exploit this weakness to launch serious attacks, potentially leading to data theft, system compromise, or other malicious activities. XML Parse.java fails to properly validate and sanitize XML input, allowing attackers to inject and manipulate external entities. It is essential for users to upgrade to the latest version of yimioa to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.