PT-2025-3862 · Guangzhou Huayi Intelligent Technology · Jeewms
Rabbit
·
Published
2025-01-11
·
Updated
2025-01-11
·
CVE-2025-0391
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
The vulnerable software is Guangzhou Huayi Intelligent Technology Jeewms, specifically versions up to 20241229.
The vulnerability is a critical SQL injection issue that affects the function saveOrUpdate of the file org/jeecgframework/web/cgform/controller/build/CgFormBuildController.java.
This vulnerability can be exploited remotely, and a public exploit has been disclosed, making it possible for attackers to use it.
To address this issue, it is recommended to upgrade to version 20250101.
The vulnerability has been assigned the CVE identifier CVE-2025-0391.
#GuangzhouHuayiIntelligentTechnology #Jeewms #SQLInjection #CVE20250391 #RemoteExploitation #PublicExploit #UpgradeRecommended #CyberSecurity #VulnerabilityDisclosure
Exploit
Fix
Special Elements Injection
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Jeewms