CVE-2025-3241

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Apr 4, 2025
Updated: Apr 7, 2025
CWE ID 252
CWE ID 393

Summary

CVE-2025-3241 is a vulnerability affecting the zhangyanbo2007 youkefu software up to version 4.2.0. This issue lies in the CallCenterRouterController.java file, specifically the XML Document Handler component. An attacker can exploit this vulnerability by manipulating the routercontent argument, leading to xml external entity references. This type of attack allows an attacker to initiate the assault remotely, and the exploit for this vulnerability has been publicly disclosed.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • XMLSoft Libxml 2
  • libxml2

Affected Vendors

  • GNOME Project
  • Xmlsoft