Stats Digest Feeds
โ† Back to all CVEs

CVE-2025-71428

MEDIUM NVD
CVSS Score 4.9
Severity MEDIUM
Published Oct 08, 2026
Vendor unknown

Description

Jivejdon through 5.0 contains a sql injection vulnerability in AccountDaoSql.getAccountByNameLike() that allows authenticated administrators to inject SQL via the username parameter. Attackers with the Admin role can submit crafted input to /admin/user/userListAction to read database contents, including other accounts' password hashes.

References