Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-3318

Опубликовано: 06 апр. 2025
Источник: nvd
CVSS3: 6.3
CVSS2: 6.5
EPSS Низкий

Описание

A vulnerability classified as critical was found in Kenj_Frog 肯尼基蛙 company-financial-management 公司财务管理系统 1.0. Affected by this vulnerability is the function page of the file src/main/java/com/controller/ShangpinleixingController.java. The manipulation of the argument sort leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. This product takes the approach of rolling releases to provide continious delivery. Therefore, version details for affected and updated releases are not available.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:kennifrog:company_financial_management_system:1.0:*:*:*:*:*:*:*

EPSS

Процентиль: 27%
0.00096
Низкий

6.3 Medium

CVSS3

6.5 Medium

CVSS2

Дефекты

CWE-74
CWE-89

Связанные уязвимости

CVSS3: 6.3
github
10 месяцев назад

A vulnerability classified as critical was found in Kenj_Frog 肯尼基蛙 company-financial-management 公司财务管理系统 1.0. Affected by this vulnerability is the function page of the file src/main/java/com/controller/ShangpinleixingController.java. The manipulation of the argument sort leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. This product takes the approach of rolling releases to provide continious delivery. Therefore, version details for affected and updated releases are not available.

EPSS

Процентиль: 27%
0.00096
Низкий

6.3 Medium

CVSS3

6.5 Medium

CVSS2

Дефекты

CWE-74
CWE-89