CVE-2025-71428: Banq Jivejdon
Medium severity, CVSS 4.9. EPSS: 0.4% chance of exploitation in the next 30 days.
Jivejdon through 5.0 contains a sql injection vulnerability in AccountDaoSql.getAccountByNameLike() that allows authenticated administrators to inject SQL via the username parameter. Attackers with the Admin role can submit crafted input to /admin/user/userListAction to read database contents, including other accounts' password hashes.
Affected products
- Banq Jivejdon: up to and including 5.0
Published 2026-10-08. Last modified 2026-10-09.