CNNVD-202507-2560 Information

CNNVD ID

CNNVD-202507-2560

CVE-2025-7888

  • CNNVD Published: 2025-07-20

Description (Chinese)

TDuckCloud tduck-platform是中国众达数蔚(TDuckCloud)公司的一个开源表单调查系统。 TDuckCloud tduck-platform 5.1版本存在注入漏洞,该漏洞源于对文件UserFormDataMapper.java中函数UserFormDataMapper的参数formKey的错误操作,导致SQL注入。

Description (English)

TDuckCloud tduck-platform is an open-source form survey system for the Chinese company TDuckCloud. TDuckClaud tduck-platform 5.1 has an injection loophole, which results from the error of the parameter forformKey of the UserFormDataMapper.java function UserFormDataMapper, which led to the injection of SQL.

Hazard Level

High

Vulnerability Type

注入

Affected Vendor

众达数蔚

Published

2025-07-20

Last Modified

2026-02-24

References

https://vuldb.com/?ctiid.317003 https://vuldb.com/?submit.615210 https://github.com/kaixliu56/public_vulns/blob/main/TDuck-sqli.md https://vuldb.com/?id.317003 https://access.redhat.com/security/cve/cve-2025-7888

Share on: