PT-2025-53415 · Unknown · Ketr Jepaas

Red0_Ha1Yu

·

Published

2025-12-25

·

Updated

2025-12-26

·

CVE-2025-15088

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions ketr JEPaaS versions up to 7.2.8
Description A SQL injection issue exists in ketr JEPaaS. The postilService.loadPostils function, located in the file /je/postil/postil/loadPostil, is susceptible to exploitation. Manipulation of the keyWord argument can lead to SQL injection. Remote exploitation is possible.
Recommendations Versions prior to 7.2.8 should be updated. As a temporary workaround, consider restricting access to the postilService.loadPostils function until a patch is available.

Exploit

Fix

Special Elements Injection

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2025-15088

Affected Products

Ketr Jepaas