Medium severity4.3NVD Advisory· Published May 5, 2025· Updated Jun 17, 2026
CVE-2025-4260
CVE-2025-4260
Description
A vulnerability was found in zhangyanbo2007 youkefu up to 4.2.0 and classified as problematic. Affected by this issue is the function impsave of the file m\web\handler\admin\system\TemplateController.java. The manipulation of the argument dataFile leads to deserialization. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2<=4.2.0+ 1 more
- (no CPE)range: <=4.2.0
- (no CPE)range: 4.0
Patches
Vulnerability mechanics
References
4- github.com/Serein123y/vulnerability/blob/main/vul.mdnvdExploitThird Party Advisory
- vuldb.comnvdThird Party AdvisoryVDB Entry
- vuldb.comnvdThird Party AdvisoryVDB Entry
- vuldb.comnvdPermissions RequiredVDB Entry
News mentions
0No linked articles in our index yet.