CVE-2025-3241
CVSS 3.1 Score 7.5 of 10 (high)
Details
Published Apr 4, 2025
Updated: Apr 7, 2025
CWE ID 252
CWE ID 393
Summary
CVE-2025-3241 is a vulnerability affecting the zhangyanbo2007 youkefu software up to version 4.2.0. This issue lies in the CallCenterRouterController.java file, specifically the XML Document Handler component. An attacker can exploit this vulnerability by manipulating the routercontent argument, leading to xml external entity references. This type of attack allows an attacker to initiate the assault remotely, and the exploit for this vulnerability has been publicly disclosed.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- XMLSoft Libxml 2
- libxml2
Affected Vendors
- GNOME Project
- Xmlsoft