6.1
CVSSv3

CVE-2025-25589

CVSSv4: NA | CVSSv3: 6.1 | CVSSv2: NA | VMScore: 710 | EPSS: 0.00067 | KEV: Not Included
Published: 18/03/2025 Updated: 19/03/2025

Vulnerability Summary

XXE Code Execution Vulnerability in Yimioa Before v2024.07.04

An XML external entity (XXE) injection vulnerability exists in the /weixin/aes/XMLParse.java component of yimioa before version 2024.07.04. This vulnerability enables attackers to execute arbitrary code by providing a carefully crafted XML file. The issue affects the software's XML parsing mechanism, which can be manipulated to perform unauthorized actions.