CVE-2025-4260 | zhangyanbo2007 youkefu up to 4.2.0 TemplateController.java impsave dataFile deserialization
A vulnerability was found in zhangyanbo2007 youkefu up to 4.2.0. It has been rated as critical. Affected by this issue is the function impsave of the file m\web\handler\admin\system\TemplateController.java. This manipulation of the argument dataFile causes deserialization.
This vulnerability appears as CVE-2025-4260. The attack may be initiated remotely. In addition, an exploit is available.