NA
CVSSv2

CVE-2025-25589

CVSSv4: NA | CVSSv3: 8.1 | CVSSv2: NA | VMScore: 910 | EPSS: 0.00078 | KEV: Not Included
Published: 18/03/2025 Updated: 21/03/2025

Vulnerability Summary

XXE Code Execution Vulnerability in Yimioa Before v2024.07.04

An XML external entity (XXE) injection vulnerability exists in the /weixin/aes/XMLParse.java component of yimioa before version 2024.07.04. This vulnerability enables attackers to execute arbitrary code by providing a carefully crafted XML file. The issue affects the software's XML parsing mechanism, which can be manipulated to perform unauthorized actions.