CVE-2025-25768
CVSS 3.1 Score 5.4 of 10 (medium)
Details
Summary
CVE-2025-25768 is a newly identified server-side template injection (SSTI) vulnerability affecting MRCMS v3.1.2. The issue lies in the DispatcherServlet.java component, which can be exploited by attackers to execute arbitrary code by sending specially crafted payloads. This vulnerability poses a significant risk, as it enables code execution on the server-side without requiring user interaction. Successful exploitation could result in unauthorized access, data theft, or system compromise. Users of MRCMS v3.1.2 are urged to apply the available patch or upgrade to a secure version as soon as possible.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.