CVE-2025-71428 — Jivejdon through 5.0 contains a sql injection vulnerability in AccountDaoSql.getAccountByNameLike() that allows authenticated administrators to inj…
Description
Jivejdon through 5.0 contains a sql injection vulnerability in AccountDaoSql.getAccountByNameLike() that allows authenticated administrators to inject SQL via the username parameter. Attackers with the Admin role can submit crafted input to /admin/user/userListAction to read database contents, including other accounts' password hashes.
CVSS v4.0 base metrics
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XMedium severity
Band computed from the CVSS base score, not the source's own label — so it means the same thing across every feed.
AV
Network
Attack Vector
AC
Low
Attack Complexity
AT
None
Attack Requirements
PR
High
Privileges Required
UI
None
User Interaction
VC
High
Confidentiality (Vulnerable System)
VI
None
Integrity (Vulnerable System)
VA
None
Availability (Vulnerable System)
SC
None
Confidentiality (Subsequent System)
SI
None
Integrity (Subsequent System)
SA
None
Availability (Subsequent System)
References
- advisory[email protected]https://github.com/banq/jivejdon
- advisory[email protected]https://github.com/banq/jivejdon/blob/ee67a65e65228644a71c8317d7e34deea50f95ef/src/main/java/com/jdon/jivejdon/infrastructure/repository/dao/sql/AccountDaoSql.java#L329-L335
- advisory[email protected]https://github.com/banq/jivejdon/blob/ee67a65e65228644a71c8317d7e34deea50f95ef/src/main/java/com/jdon/jivejdon/presentation/action/admin/UserListAction.java#L13-L24
- advisory[email protected]https://github.com/banq/jivejdon/issues/24
- advisory[email protected]https://github.com/banq/jivejdon/issues/28
- advisory[email protected]https://www.vulncheck.com/advisories/jivejdon-through-5.0-sql-injection-via-username-in-userlistaction
Related threats
same CWE or vendorCVE-2026-84209 — IBM Guardium Data Protection 12.2.2, and 12.1 could allow a remote attacker to execute arbitrary SQL commands due to improper neutralization of spe…
CVE-2026-84209 · 2h ago
CVE-2026-81932 — IBM Guardium Data Protection 12.0, 12.1, and 12.2 is vulnerable to SQL injection.
CVE-2026-81932 · 2h ago
CVE-2026-80381 — IBM Guardium Data Protection 12.0, 12.1, and 12.2 could allow a remote attacker to execute unauthorized SQL statements due to SQL injection.
CVE-2026-80381 · 2h ago
CVE-2026-16830 — IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 could allow a remote authenticated attacker to …
CVE-2026-16830 · 3h ago
CVE-2026-107385 — MariaDB Connector/Node.js is used to connect applications developed on Node.js to MariaDB and MySQL databases.
CVE-2026-107385 · 5h ago
CVE-2026-107384 — MariaDB Connector/Node.js is used to connect applications developed on Node.js to MariaDB and MySQL databases.
CVE-2026-107384 · 5h ago