Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-15251

Опубликовано: 30 дек. 2025
Источник: nvd
CVSS3: 5.6
CVSS2: 5.1
EPSS Низкий

Описание

A vulnerability was detected in beecue FastBee up to 2.1. Impacted is the function getRootElement of the file springboot/fastbee-server/sip-server/src/main/java/com/fastbee/sip/handler/req/ReqAbstractHandler.java of the component SIP Message Handler. The manipulation results in xml external entity reference. It is possible to launch the attack remotely. A high complexity level is associated with this attack. The exploitability is considered difficult. The project owner replied to the issue report: "Okay, we'll handle it as soon as possible."

EPSS

Процентиль: 20%
0.00063
Низкий

5.6 Medium

CVSS3

5.1 Medium

CVSS2

Дефекты

CWE-610

Связанные уязвимости

CVSS3: 5.6
github
около 1 месяца назад

A vulnerability was detected in beecue FastBee up to 2.1. Impacted is the function getRootElement of the file springboot/fastbee-server/sip-server/src/main/java/com/fastbee/sip/handler/req/ReqAbstractHandler.java of the component SIP Message Handler. The manipulation results in xml external entity reference. It is possible to launch the attack remotely. A high complexity level is associated with this attack. The exploitability is considered difficult. The project owner replied to the issue report: "Okay, we'll handle it as soon as possible."

EPSS

Процентиль: 20%
0.00063
Низкий

5.6 Medium

CVSS3

5.1 Medium

CVSS2

Дефекты

CWE-610