CNNVD-202512-4759 Information

CNNVD ID

CNNVD-202512-4759

CVE-2025-15088

  • CNNVD Published: 2025-12-25

Description (Chinese)

ketr JEPaaS是中国凯特伟业(ketr)开源的一个低代码快速开发平台。 ketr JEPaaS 7.2.8及之前版本存在SQL注入漏洞,该漏洞源于对文件/je/postil/postil/loadPostil中函数postilService.loadPostils的参数keyWord的错误操作,可能导致SQL注入攻击。

Description (English)

Ketr JePaaS is a low-code, fast-development platform for the open source of Kate West in China. Ketr JEPaS 7.2.8 and previous versions had an injection loophole in SQL, which stemmed from the error of the parameter keyWord for the function postilService.loadPostil in document/je/postil/postil/loadPostil, which could lead to an attack on SQL injection.

Hazard Level

High

Vulnerability Type

SQL注入

Affected Vendor

凯特伟业

Published

2025-12-25

Last Modified

2026-02-24

References

https://github.com/ha1yu-Yiqiyin/warehouse/blob/main/jepaas-v7.2.8-sqlinject1.md#2%E5%A4%8D%E7%8E%B0replicate https://vuldb.com/?id.338416 https://vuldb.com/?ctiid.338416 https://vuldb.com/?submit.708321 https://access.redhat.com/security/cve/cve-2025-15088

Share on: