CVE-2025-25768

CVSS 3.1 Score 5.4 of 10 (medium)

Details

Published Feb 21, 2025
Updated: Mar 3, 2025
CWE ID 77

Summary

CVE-2025-25768 is a newly identified server-side template injection (SSTI) vulnerability affecting MRCMS v3.1.2. The issue lies in the DispatcherServlet.java component, which can be exploited by attackers to execute arbitrary code by sending specially crafted payloads. This vulnerability poses a significant risk, as it enables code execution on the server-side without requiring user interaction. Successful exploitation could result in unauthorized access, data theft, or system compromise. Users of MRCMS v3.1.2 are urged to apply the available patch or upgrade to a secure version as soon as possible.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share