CNNVD-202512-4759 Information
CNNVD ID
CNNVD-202512-4759
Related CVE
- CNNVD Published: 2025-12-25
Description (Chinese)
ketr JEPaaS是中国凯特伟业(ketr)开源的一个低代码快速开发平台。 ketr JEPaaS 7.2.8及之前版本存在SQL注入漏洞,该漏洞源于对文件/je/postil/postil/loadPostil中函数postilService.loadPostils的参数keyWord的错误操作,可能导致SQL注入攻击。
Description (English)
Ketr JePaaS is a low-code, fast-development platform for the open source of Kate West in China. Ketr JEPaS 7.2.8 and previous versions had an injection loophole in SQL, which stemmed from the error of the parameter keyWord for the function postilService.loadPostil in document/je/postil/postil/loadPostil, which could lead to an attack on SQL injection.
Hazard Level
High
Vulnerability Type
SQL注入
Affected Vendor
凯特伟业
Published
2025-12-25
Last Modified
2026-02-24
References
https://github.com/ha1yu-Yiqiyin/warehouse/blob/main/jepaas-v7.2.8-sqlinject1.md#2%E5%A4%8D%E7%8E%B0replicate https://vuldb.com/?id.338416 https://vuldb.com/?ctiid.338416 https://vuldb.com/?submit.708321 https://access.redhat.com/security/cve/cve-2025-15088
Share on: