Deserialization Vulnerability in Youkefu by Zhangyanbo2007
CVE-2025-4260
Key Information:
- Vendor
- Zhangyanbo2007
- Status
- Vendor
- CVE Published:
- 5 May 2025
Badges
Summary
A deserialization vulnerability has been identified in the Youkefu product from Zhangyanbo2007, specifically within the impsave function located in the TemplateController.java file. This flaw allows an attacker to manipulate the argument dataFile, potentially enabling remote exploitation. Malicious actors may leverage this vulnerability to unearth sensitive information or modify application behavior. Disclosure of the exploit has raised concerns regarding its public availability, emphasizing the need for immediate attention to secure coding practices and timely updates.
Affected Version(s)
youkefu 4.0
youkefu 4.1
youkefu 4.2.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved