CVE-2025-12140
Severity CVSS v4.0:
CRITICAL
Type:
Unavailable / Other
Publication date:
27/11/2025
Last modified:
27/11/2025
Description
The application contains an insecure &#39;redirectToUrl&#39; mechanism that incorrectly processes the value of the &#39;redirectUrlParameter&#39; parameter. The application interprets the entered string of characters as a Java expression, allowing an unauthenticated attacer to perform arbitrary code execution.<br />
This issue was fixed in version wu#2016.1.5513#0#20251014_113353
Impact
Base Score 4.0
9.30
Severity 4.0
CRITICAL



