CVE-2025-3322

An improper neutralization of inputs used in expression language allows remote code execution with the highest privileges on the server.
CVSS

No CVSS.

References
Configurations

No configuration.

History

06 Jun 2025, 09:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-06-06 09:15

Updated : 2025-06-06 14:07


NVD link : CVE-2025-3322

Mitre link : CVE-2025-3322

CVE.ORG link : CVE-2025-3322


JSON object : View

Products Affected

No product.

CWE
CWE-917

Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection')