| CVE ID | CVE-2025-12140 |
| Publication date | 27 November 2025 |
| Vendor | Simple SA |
| Product | Wirtualna Uczelnia |
| Vulnerable versions | All before wu#2016.1.5513#0#20251014_113353 |
| Vulnerability type (CWE) | Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') (CWE-95) |
| Report source | Report to CERT Polska |
Description
CERT Polska has received a report about vulnerability in Wirtualna Uczelnia software and participated in coordination of its disclosure.
The vulnerability CVE-2025-12140: The application incorrectly processes the value of the 'redirectUrlParameter' parameter in the endpoint 'redirectToUrl'. The application interprets the entered string of characters as a Java expression, allowing an unauthenticated attacker to perform arbitrary code execution. This issue was fixed in version wu#2016.1.5513#0#20251014_113353
Credits
We thank Marcin Ressel for the responsible vulnerability report.
More about the coordinated vulnerability disclosure process at CERT Polska can be found at https://cert.pl/en/cvd/.