CNNVD-202507-2560 Information
Jul 20, 2025
cve
CNNVD ID
CNNVD-202507-2560
Related CVE
- CNNVD Published: 2025-07-20
Description (Chinese)
TDuckCloud tduck-platform是中国众达数蔚(TDuckCloud)公司的一个开源表单调查系统。 TDuckCloud tduck-platform 5.1版本存在注入漏洞,该漏洞源于对文件UserFormDataMapper.java中函数UserFormDataMapper的参数formKey的错误操作,导致SQL注入。
Description (English)
TDuckCloud tduck-platform is an open-source form survey system for the Chinese company TDuckCloud. TDuckClaud tduck-platform 5.1 has an injection loophole, which results from the error of the parameter forformKey of the UserFormDataMapper.java function UserFormDataMapper, which led to the injection of SQL.
Hazard Level
High
Vulnerability Type
注入
Affected Vendor
众达数蔚
Published
2025-07-20
Last Modified
2026-02-24
References
https://vuldb.com/?ctiid.317003 https://vuldb.com/?submit.615210 https://github.com/kaixliu56/public_vulns/blob/main/TDuck-sqli.md https://vuldb.com/?id.317003 https://access.redhat.com/security/cve/cve-2025-7888
Share on: