CVE-2025-71428: medium-severity vulnerability in banq jivejdon
Jivejdon through 5.0 SQL Injection via username in userListAction
Published
10Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 6.9
exploitation probability
—
observed exploitation
nono source reports it
Jivejdon through 5.0 contains a sql injection vulnerability in AccountDaoSql.getAccountByNameLike() that allows authenticated administrators to inject SQL via the username parameter. Attackers with the Admin role can submit crafted input to /admin/user/userListAction to read database contents, including other accounts' password hashes.
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Affected products
banq · jivejdonRelated CVEs — banq jivejdon
In the same product, most dangerous first.
CVE-2026-107831MEDIUMJivejdon through 5.0 CSRF via GET-based Account and Thread ActionsEPSS —CVE-2026-107830MEDIUMJivejdon through commit ee67a65e Missing Rate Limiting via /account/smsVRAction SMS EndpointEPSS —CVE-2026-107829HIGHJivejdon through 5.0 Unsalted MD5 Password Storage via AccountDaoSqlEPSS —CVE-2026-107828MEDIUMJivejdon through 5.0 Predictable Passwords via Sina Weibo OAuth LoginEPSS —CVE-2026-107801MEDIUMJivejdon through 5.0 Stored XSS via Attachment Upload Content-TypeEPSS —CVE-2026-107800MEDIUMJivejdon through 5.0 Stored XSS via Private Short MessagesEPSS —
References
https://github.com/banq/jivejdonhttps://github.com/banq/jivejdon/blob/ee67a65e65228644a71c8317d7e34deea50f95ef/src/main/java/com/jdon/jivejdon/infrastructure/repository/dao/sql/AccountDaoSql.java#L329-L335https://github.com/banq/jivejdon/blob/ee67a65e65228644a71c8317d7e34deea50f95ef/src/main/java/com/jdon/jivejdon/presentation/action/admin/UserListAction.java#L13-L24https://github.com/banq/jivejdon/issues/24https://github.com/banq/jivejdon/issues/28https://www.vulncheck.com/advisories/jivejdon-through-5.0-sql-injection-via-username-in-userlistaction