CVE Vulnerabilities

CVE-2025-2365

Externally Controlled Reference to a Resource in Another Sphere

Published: Mar 17, 2025 | Modified: Mar 17, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

A vulnerability, which was classified as problematic, has been found in crmeb_java up to 1.3.4. Affected by this issue is the function webHook of the file WeChatMessageController.java. The manipulation leads to xml external entity reference. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

Weakness

The product uses an externally controlled name or reference that resolves to a resource that is outside of the intended control sphere.

References