Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-12140

Опубликовано: 27 нояб. 2025
Источник: nvd
EPSS Низкий

Описание

The application contains an insecure 'redirectToUrl' mechanism that incorrectly processes the value of the 'redirectUrlParameter' parameter. The application interprets the entered string of characters as a Java expression, allowing an unauthenticated attacer to perform arbitrary code execution. This issue was fixed in version wu#2016.1.5513#0#20251014_113353

EPSS

Процентиль: 35%
0.00411
Низкий

Дефекты

CWE-95

Связанные уязвимости

github
10 месяцев назад

The application contains an insecure 'redirectToUrl' mechanism that incorrectly processes the value of the 'redirectUrlParameter' parameter. The application interprets the entered string of characters as a Java expression, allowing an unauthenticated attacer to perform arbitrary code execution. This issue was fixed in version wu#2016.1.5513#0#20251014_113353

EPSS

Процентиль: 35%
0.00411
Низкий

Дефекты

CWE-95