CVE-2025-12140
Gravedad CVSS v4.0:
CRÍTICA
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
27/11/2025
Última modificación:
27/11/2025
Descripción
*** Pendiente de traducción *** The application contains an insecure &#39;redirectToUrl&#39; mechanism that incorrectly processes the value of the &#39;redirectUrlParameter&#39; parameter. The application interprets the entered string of characters as a Java expression, allowing an unauthenticated attacer to perform arbitrary code execution.<br />
This issue was fixed in version wu#2016.1.5513#0#20251014_113353
Impacto
Puntuación base 4.0
9.30
Gravedad 4.0
CRÍTICA



