CVE-2025-71428: Banq Jivejdon

Medium severity, CVSS 4.9. EPSS: 0.4% chance of exploitation in the next 30 days.

Jivejdon through 5.0 contains a sql injection vulnerability in AccountDaoSql.getAccountByNameLike() that allows authenticated administrators to inject SQL via the username parameter. Attackers with the Admin role can submit crafted input to /admin/user/userListAction to read database contents, including other accounts' password hashes.

Affected products

  • Banq Jivejdon: up to and including 5.0

Published 2026-10-08. Last modified 2026-10-09.