📦 Youkefu

by Zhangyanbo2007

🔍 What is Youkefu?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-4260

MEDIUM CVSS 4.3 May 5, 2025

This vulnerability in Youkefu up to version 4.2.0 allows remote attackers to execute arbitrary code through insecure deserialization in the TemplateController.java file. Attackers can exploit this by ...

CVE-2025-4258

MEDIUM CVSS 6.3 May 5, 2025

This critical vulnerability in Youkefu allows remote attackers to upload arbitrary files without restrictions via the MediaController.java Upload function. Attackers can potentially upload malicious f...

CVE-2025-3241

MEDIUM CVSS 6.3 Apr 4, 2025

This XXE vulnerability in YoukeFu allows attackers to read arbitrary files from the server by exploiting XML parsing in the call center router component. It affects YoukeFu versions up to 4.2.0 and ca...

CVE-2025-2997

MEDIUM CVSS 6.3 Mar 31, 2025

This critical vulnerability in Youkefu 4.2.0 allows remote attackers to perform server-side request forgery (SSRF) attacks by manipulating the 'url' parameter in the /res/url endpoint. Attackers can e...