Record summary

CVE-2025-66744 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.

Description

In Yonyou YonBIP v3 and before, the LoginWithV8 interface in the series data application service system is vulnerable to path traversal, allowing unauthorized access to sensitive information within the system

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Mar 30, 2026 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableYes
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 12, 2026 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied

Nuclei templates

1
ProjectDiscoveryHIGHYonyou YonBIP - Path TraversalCVSS 7.5

Yonyou YonBIP v3 and before contains a path traversal caused by improper validation in the LoginWithV8 interface of the series data application service system, letting unauthorized attackers access sensitive information.

Impact

Unauthorized attackers can access sensitive system information, potentially leading to data exposure.

Remediation

Update to the latest version beyond v3.

AuthorsDhiyaneshDk
Template tagscvecve2025yonbiplfivkev
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
FOFA: body="YonBIP | 数据应用服务"

Source: ProjectDiscovery

References

2