SQL Injection Vulnerability in Jivejdon Product by Banq
CVE-2025-71428
6.9MEDIUM
What is CVE-2025-71428?
Jivejdon versions up to 5.0 are susceptible to a SQL injection flaw that allows authenticated administrators to manipulate SQL queries through the username parameter in the AccountDaoSql.getAccountByNameLike() method. This vulnerability enables attackers with administrator privileges to exploit the /admin/user/userListAction endpoint, potentially exposing sensitive database content, including password hashes for other user accounts. Prompt action is advised to mitigate the risks associated with this security issue.
Affected Version(s)
jivejdon 0 <= 5.0
