216.73.217.80

CVE-2025-2365

· Published 17/03/2025 07:15 · Modified 17/03/2025 07:15

Labels: CVE-2025-2365 2025-03-17CVE-2025-2365CWE-610[email protected]

Essential information

Published
17/03/2025 07:15
Modified
17/03/2025 07:15
Author
Creator
CVSS
6.3 MEDIUM (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

CVSS metrics

Description

A vulnerability, which was classified as problematic, has been found in crmeb_java up to 1.3.4. Affected by this issue is the function webHook of the file WeChatMessageController.java. The manipulation leads to xml external entity reference. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

NVD status

Status
Awaiting Analysis — CVE has been marked for Analysis. Normally once in this state the CVE will be analyzed by NVD staff within 24 hours.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
crmeb / crmeb java cpe:2.3:a:crmeb:crmeb_java:*:*:*:*:*:*:*:*

References