CVE-2025-25585: r1bbit Yimioa

High severity, CVSS 7.3. EPSS: 0.3% chance of exploitation in the next 30 days.

Incorrect access control in the component /config/WebSecurityConfig.java of yimioa before v2024.07.04 allows unauthorized attackers to arbitrarily modify Administrator passwords.

Affected products

  • r1bbit Yimioa: before 2024.07.04 (fixed in 2024.07.04)

Published 2025-03-18. Last modified 2026-06-17.