CVE-2025-66744
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Record summary
CVE-2025-66744 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.
Description
In Yonyou YonBIP v3 and before, the LoginWithV8 interface in the series data application service system is vulnerable to path traversal, allowing unauthorized access to sensitive information within the system
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Mar 30, 2026 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 12, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
YonBIPBrowse Yonyou / YonBIP | VulnCheck | Version data not supplied | |
Nuclei templates
1ProjectDiscoveryHIGHYonyou YonBIP - Path TraversalCVSS 7.5
Yonyou YonBIP v3 and before contains a path traversal caused by improper validation in the LoginWithV8 interface of the series data application service system, letting unauthorized attackers access sensitive information.
Impact
Unauthorized attackers can access sensitive system information, potentially leading to data exposure.
Remediation
Update to the latest version beyond v3.
Source: ProjectDiscovery