Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-13326 | A vulnerability was found in zhangyanbo2007 youkefu up to 4.2.0 and classified as problematic. Affected by this issue is the function impsave of the file m\web\handler\admin\system\TemplateController.java. The manipulation of the argument dataFile leads to deserialization. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. |
Fri, 10 Oct 2025 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Zhangyanbo2007
Zhangyanbo2007 youkefu |
|
| CPEs | cpe:2.3:a:zhangyanbo2007:youkefu:4.2.0:*:*:*:*:*:*:* | |
| Vendors & Products |
Zhangyanbo2007
Zhangyanbo2007 youkefu |
Sat, 12 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Mon, 05 May 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 05 May 2025 03:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was found in zhangyanbo2007 youkefu up to 4.2.0 and classified as problematic. Affected by this issue is the function impsave of the file m\web\handler\admin\system\TemplateController.java. The manipulation of the argument dataFile leads to deserialization. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. | |
| Title | zhangyanbo2007 youkefu TemplateController.java impsave deserialization | |
| Weaknesses | CWE-20 CWE-502 |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2025-05-05T13:53:02.461Z
Reserved: 2025-05-04T07:07:35.915Z
Link: CVE-2025-4260
Updated: 2025-05-05T13:52:55.269Z
Status : Analyzed
Published: 2025-05-05T03:15:23.660
Modified: 2025-10-10T17:29:14.263
Link: CVE-2025-4260
No data.
OpenCVE Enrichment
No data.
EUVD