CVE-2025-24404 | Apache HertzBeat up to 1.6.x HTTP Sitemap XML Response Parser xml injection
A vulnerability classified as critical has been found in Apache HertzBeat up to 1.6.x. This affects an unknown function of the component HTTP Sitemap XML Response Parser. The manipulation leads to xml injection.
This vulnerability is traded as CVE-2025-24404. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.