CVE-2025-12140: Simple Sa Wirtualna Uczelnia

Critical severity, CVSS 9.3. EPSS: 0.4% chance of exploitation in the next 30 days.

The application contains an insecure 'redirectToUrl' mechanism that incorrectly processes the value of the 'redirectUrlParameter' parameter. The application interprets the entered string of characters as a Java expression, allowing an unauthenticated attacer to perform arbitrary code execution. This issue was fixed in version wu#2016.1.5513#0#20251014_113353

Affected products

Published 2025-11-27. Last modified 2026-06-17.