CVE-2025-12140

Severity CVSS v4.0:
CRITICAL
Type:
Unavailable / Other
Publication date:
27/11/2025
Last modified:
27/11/2025

Description

The application contains an insecure &amp;#39;redirectToUrl&amp;#39; mechanism that incorrectly processes the value of the &amp;#39;redirectUrlParameter&amp;#39; parameter. The application interprets the entered string of characters as a Java expression, allowing an unauthenticated attacer to perform arbitrary code execution.<br /> This issue was fixed in version wu#2016.1.5513#0#20251014_113353

References to Advisories, Solutions, and Tools