CVE-2025-13268: Dromara Datacompare
Medium severity, CVSS 6.3. EPSS: 0.3% chance of exploitation in the next 30 days.
A flaw has been found in Dromara dataCompare up to 1.0.1. The affected element is the function DbConfig of the file src/main/java/com/vince/xq/project/system/dbconfig/service/DbconfigServiceImpl.java of the component JDBC URL Handler. Executing manipulation can lead to injection. The attack can be launched remotely. The exploit has been published and may be used.
Affected products
- Dromara Datacompare: version 1.0.0 only; version 1.0.1 only
Published 2025-11-17. Last modified 2026-10-07.