First published: Mon May 05 2025(Updated: )
A vulnerability was found in zhangyanbo2007 youkefu up to 4.2.0 and classified as problematic. Affected by this issue is the function impsave of the file m\web\handler\admin\system\TemplateController.java. The manipulation of the argument dataFile leads to deserialization. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Credit: cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
zhangyanbo2007 youkefu | <=4.2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-4260 is classified as problematic due to its potential for remote code execution through deserialization.
To fix CVE-2025-4260, you should upgrade zhangyanbo2007 youkefu to a version higher than 4.2.0 that addresses this vulnerability.
CVE-2025-4260 affects the impsave function in the TemplateController.java file of the zhangyanbo2007 youkefu application.
CVE-2025-4260 is a deserialization vulnerability that can be exploited through manipulation of the dataFile argument.
Any users of zhangyanbo2007 youkefu versions up to and including 4.2.0 may be impacted by CVE-2025-4260.