CVE-2025-13268: Dromara Datacompare

Medium severity, CVSS 6.3. EPSS: 0.3% chance of exploitation in the next 30 days.

A flaw has been found in Dromara dataCompare up to 1.0.1. The affected element is the function DbConfig of the file src/main/java/com/vince/xq/project/system/dbconfig/service/DbconfigServiceImpl.java of the component JDBC URL Handler. Executing manipulation can lead to injection. The attack can be launched remotely. The exploit has been published and may be used.

Affected products

  • Dromara Datacompare: version 1.0.0 only; version 1.0.1 only

Published 2025-11-17. Last modified 2026-10-07.