Zhangyanbo2007 Youkefu vulnerabilities
5 known vulnerabilities affecting zhangyanbo2007/youkefu.
Total CVEs
5
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH3
Vulnerabilities
Page 1 of 1
CVE-2025-3381P2CRITICALCVSS 9.8v4.2.02025-04-07
CVE-2025-3381 [CRITICAL] CWE-22 CVE-2025-3381: A vulnerability, which was classified as critical, was found in zhangyanbo2007 youkefu 4.2.0. This a
A vulnerability, which was classified as critical, was found in zhangyanbo2007 youkefu 4.2.0. This affects an unknown part of the file WebIMController.java of the component File Upload. The manipulation of the argument ID leads to path traversal. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be u
nvd
CVE-2025-4258P2HIGHCVSS 8.8≥ 4.0, ≤ 4.2.0v4.0+2 more2025-05-05
CVE-2025-4258 [HIGH] CWE-284 CVE-2025-4258: A vulnerability, which was classified as critical, was found in zhangyanbo2007 youkefu up to 4.2.0.
A vulnerability, which was classified as critical, was found in zhangyanbo2007 youkefu up to 4.2.0. Affected is the function Upload of the file \youkefu-master\src\main\java\com\ukefu\webim\web\handler\resource\MediaController.java. The manipulation of the argument imgFile leads to unrestricted upload. It is possible to launch the attack remotely. The ex
nvd
CVE-2025-3241P3CRITICALCVSS 9.8v4.2.0v4.0+2 more2025-04-04
CVE-2025-3241 [CRITICAL] CWE-610 CVE-2025-3241: A vulnerability, which was classified as problematic, was found in zhangyanbo2007 youkefu up to 4.2.
A vulnerability, which was classified as problematic, was found in zhangyanbo2007 youkefu up to 4.2.0. This affects an unknown part of the file src/main/java/com/ukefu/webim/web/handler/admin/callcenter/CallCenterRouterController.java of the component XML Document Handler. The manipulation of the argument routercontent leads to xml external entity r
nvd
CVE-2025-2997P3HIGHCVSS 8.8v4.2.02025-03-31
CVE-2025-2997 [HIGH] CWE-918 CVE-2025-2997: A vulnerability was found in zhangyanbo2007 youkefu 4.2.0. It has been classified as critical. Affec
A vulnerability was found in zhangyanbo2007 youkefu 4.2.0. It has been classified as critical. Affected is an unknown function of the file /res/url. The manipulation of the argument url leads to server-side request forgery. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
nvd
CVE-2025-4260P3HIGHCVSS 8.3v4.2.0v4.0+1 more2025-05-05
CVE-2025-4260 [HIGH] CWE-20 CVE-2025-4260: A vulnerability was found in zhangyanbo2007 youkefu up to 4.2.0 and classified as problematic. Affec
A vulnerability was found in zhangyanbo2007 youkefu up to 4.2.0 and classified as problematic. Affected by this issue is the function impsave of the file m\web\handler\admin\system\TemplateController.java. The manipulation of the argument dataFile leads to deserialization. The attack may be launched remotely. The exploit has been disclosed to the public
nvd