Back to search
CVE-2025-12140
Published: Nov 27, 2025
Modified: Nov 28, 2025
PUBLISHED
Description
The application contains an insecure 'redirectToUrl' mechanism that incorrectly processes the value of the 'redirectUrlParameter' parameter. The application interprets the entered string of characters as a Java expression, allowing an unauthenticated attacer to perform arbitrary code execution. This issue was fixed in version wu#2016.1.5513#0#20251014_113353
| Vendor | Product | Versions |
|---|---|---|
Simple SA | Wirtualna Uczelnia | affected 0 - < wu#2016.1.5513#0#20251014_113353 |
Weaknesses (CWE)
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now