Vendorsr1bbityimioaall versions
Vulnerabilities

r1bbit Yimioa

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

10CVEs
CVE-2025-1226
ywoa setup.jsp improper authorization
Published 2025-02-12 · Analyzed
9.8EPSS 0.008
CVE-2025-1216
ywoa OaNoticeMapper.xml selectNoticeList sql injection
Published 2025-02-12 · Analyzed
8.8EPSS 0.005
CVE-2025-1227
ywoa AddressDao.xml selectList sql injection
Published 2025-02-12 · Analyzed
8.8EPSS 0.005
CVE-2025-1224
ywoa UserMapper.xml listNameBySql sql injection
Published 2025-02-12 · Analyzed
8.8EPSS 0.004
CVE-2025-25585
Incorrect access control in the component /config/WebSecurityConfig.java of yimioa before v2024.07.04 allows unauthorized attackers to arbitrarily modify Administrator passwords.
Published 2025-03-18 · Analyzed
7.3EPSS 0.003
CVE-2025-1225
ywoa WXCallBack Interface XMLParse.java extract xml external entity reference
Published 2025-02-12 · Analyzed
6.5EPSS 0.004
CVE-2025-25580
yimioa before v2024.07.04 was discovered to contain a SQL injection vulnerability via the listNameBySql() method at /xml/UserMapper.xml.
Published 2025-03-18 · Analyzed
6.1EPSS 0.002
CVE-2025-25590
yimioa before v2024.07.04 was discovered to contain a SQL injection vulnerability via the component /mapper/xml/AddressDao.xml.
Published 2025-03-18 · Analyzed
6.1EPSS 0.002
CVE-2025-25582
yimioa before v2024.07.04 was discovered to contain a SQL injection vulnerability via the selectNoticeList() method at /xml/OaNoticeMapper.xml.
Published 2025-03-18 · Analyzed
6.1EPSS 0.002
CVE-2025-25586
yimioa before v2024.07.04 was discovered to contain an information disclosure vulnerability via the component /resources/application.yml.
Published 2025-03-18 · Analyzed
4.2EPSS 0.002