Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4fp2-3xgg-jg4w

Опубликовано: 07 апр. 2026
Источник: github
Github: Прошло ревью
CVSS4: 5.5
CVSS3: 7.3

Описание

PowerJob vulnerable to SQL injection

A vulnerability was identified in PowerJob 5.1.0/5.1.1/5.1.2. Impacted is an unknown function of the file powerjob-server/powerjob-server-starter/src/main/java/tech/powerjob/server/web/controller/InstanceController.java of the component detailPlus Endpoint. The manipulation of the argument customQuery leads to sql injection. Remote exploitation of the attack is possible. The project was informed of the problem early through an issue report but has not responded yet.

Пакеты

Наименование

tech.powerjob:powerjob-server-starter

maven
Затронутые версииВерсия исправления

>= 5.1.0, <= 5.1.2

Отсутствует

EPSS

Процентиль: 19%
0.00269
Низкий

5.5 Medium

CVSS4

7.3 High

CVSS3

Дефекты

CWE-74
CWE-89

Связанные уязвимости

CVSS3: 7.3
nvd
5 месяцев назад

A vulnerability was identified in PowerJob 5.1.0/5.1.1/5.1.2. Impacted is an unknown function of the file powerjob-server/powerjob-server-starter/src/main/java/tech/powerjob/server/web/controller/InstanceController.java of the component detailPlus Endpoint. The manipulation of the argument customQuery leads to sql injection. Remote exploitation of the attack is possible. The project was informed of the problem early through an issue report but has not responded yet.

EPSS

Процентиль: 19%
0.00269
Низкий

5.5 Medium

CVSS4

7.3 High

CVSS3

Дефекты

CWE-74
CWE-89