CNNVD-202512-2738 Information

CNNVD ID

CNNVD-202512-2738

CVE-2025-14694

  • CNNVD Published: 2025-12-15

Description (Chinese)

ketr JEPaaS是中国凯特伟业(ketr)开源的一个低代码快速开发平台。 ketr JEPaaS 7.2.8及之前版本存在SQL注入漏洞,该漏洞源于对文件/je/postil/postil/readAllPostil中参数keyWord的错误操作,可能导致SQL注入。

Description (English)

Ketr JePaaS is a low-code, fast-development platform for the open source of Kate West in China. Ketr JEPaS 7.2.8 and previous versions contain an injection loophole in SQL, which is the result of an error in the parameter keyWord in document /je/postil/postil/postil/readAllPostil, which may result in SQL injection.

Hazard Level

High

Vulnerability Type

SQL注入

Affected Vendor

凯特伟业

Published

2025-12-15

Last Modified

2026-02-24

References

https://github.com/c3p000-Yiqiyin/JEPaaS-readAllPostil-SQL-Injection-Vulnerability/blob/main/README.md https://vuldb.com/?id.336412 https://vuldb.com/?ctiid.336412 https://vuldb.com/?submit.707178

Share on: