← Back to browse · API

CVE-2022-25894

Severity
CRITICAL
CVSS
9.8
EPSS
0.02575
Risk score
40.1
CISA KEV
No
PoC
No
Published
2023-01-25
Modified
2025-04-01
First seen
2026-08-07
Aliases
EUVD-2023-0410, GHSA-8M9F-C5P9-WQCH
Products
n/a:com.bstek.uflo:uflo-core 0 <*
Sources
euvd EUVD-2023-0410

Description

All versions of the package com.bstek.uflo:uflo-core are vulnerable to Remote Code Execution (RCE) in the ExpressionContextImpl class via jexl.createExpression(expression).evaluate(context); functionality, due to improper user input validation.

References