Injection Vulnerability in Dromara DataCompare JDBC URL Handler of Dromara
CVE-2025-13268
Key Information:
- Vendor
Dromara
- Status
- Vendor
- CVE Published:
- 17 November 2025
Badges
What is CVE-2025-13268?
A critical flaw has been identified in Dromara DataCompare versions up to 1.0.1, specifically within the DbConfig function located in the JDBC URL Handler. This vulnerability allows for remote attackers to execute unauthorized manipulation leading to potential injection attacks. The exploit has been published, raising concerns about the safety of applications relying on this component. Users and organizations utilizing Dromara DataCompare are advised to assess their systems and implement necessary security measures.
Affected Version(s)
dataCompare 1.0.0
dataCompare 1.0.1
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved
