CVE-2025-25585: r1bbit Yimioa
High severity, CVSS 7.3. EPSS: 0.3% chance of exploitation in the next 30 days.
Incorrect access control in the component /config/WebSecurityConfig.java of yimioa before v2024.07.04 allows unauthorized attackers to arbitrarily modify Administrator passwords.
Affected products
- r1bbit Yimioa: before 2024.07.04 (fixed in 2024.07.04)
Published 2025-03-18. Last modified 2026-06-17.