CNNVD-202512-2738 Information
Dec 15, 2025
cve
CNNVD ID
CNNVD-202512-2738
Related CVE
- CNNVD Published: 2025-12-15
Description (Chinese)
ketr JEPaaS是中国凯特伟业(ketr)开源的一个低代码快速开发平台。 ketr JEPaaS 7.2.8及之前版本存在SQL注入漏洞,该漏洞源于对文件/je/postil/postil/readAllPostil中参数keyWord的错误操作,可能导致SQL注入。
Description (English)
Ketr JePaaS is a low-code, fast-development platform for the open source of Kate West in China. Ketr JEPaS 7.2.8 and previous versions contain an injection loophole in SQL, which is the result of an error in the parameter keyWord in document /je/postil/postil/postil/readAllPostil, which may result in SQL injection.
Hazard Level
High
Vulnerability Type
SQL注入
Affected Vendor
凯特伟业
Published
2025-12-15
Last Modified
2026-02-24
References
https://github.com/c3p000-Yiqiyin/JEPaaS-readAllPostil-SQL-Injection-Vulnerability/blob/main/README.md https://vuldb.com/?id.336412 https://vuldb.com/?ctiid.336412 https://vuldb.com/?submit.707178
Share on: