CVE-2025-25590
CVSS 3.1 Score 6.1 of 10 (medium)
Details
Published Mar 18, 2025
Updated: Mar 19, 2025
CWE ID 89
Summary
CVE-2025-25590 is a newly discovered vulnerability affecting the yimioa software before version 2024.07.04. This issue involves a SQL injection weakness in the /mapper/xml/AddressDao.xml component, which could potentially allow unauthorized users to execute malicious SQL statements and gain unauthorized access to sensitive data. Successful exploitation of this vulnerability could result in significant data breaches or system compromises. Users are strongly encouraged to update their software to the latest version as soon as possible to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.