PT-2025-20601 · Unknown · Jadmin-Java

Bi8Bu

·

Published

2025-05-09

·

Updated

2025-10-10

·

CVE-2025-4494

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions JAdmin-JAVA JAdmin version 1.0
Description A critical vulnerability was found in the function toLogin of the file NoNeedLoginController.java of the component Admin Backend. The manipulation leads to improper authentication. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Recommendations As a temporary workaround, consider disabling the toLogin function until a patch is available. Restrict access to the Admin Backend component to minimize the risk of exploitation. Avoid using the NoNeedLoginController.java file in the affected API endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Authentication

Weakness Enumeration

Related Identifiers

CVE-2025-4494

Affected Products

Jadmin-Java