Metrics
Affected Vendors & Products
Tue, 04 Nov 2025 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Mon, 14 Apr 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
ssvc
|
Tue, 08 Apr 2025 23:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The DB chooser functionality in Jalios JPlatform 10 SP6 before 10.0.6 improperly neutralizes special elements used in an SQL command allows for authenticated administrative users to trigger SQL Injection. This issue affects JPlatform before 10.0.6 and a PatchPlugin release 10.0.6 was issued 2023-02-06. | The DB chooser functionality in Jalios JPlatform 10 SP6 before 10.0.6 improperly neutralizes special elements used in an SQL command allows for unauthenticated users to trigger SQL Injection. This issue affects JPlatform before 10.0.6 and a PatchPlugin release 10.0.6 was issued 2023-02-06. |
| Metrics |
cvssV3_1
|
cvssV3_1
|
Tue, 08 Apr 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 07 Apr 2025 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The DB chooser functionality in Jalios JPlatform 10 SP6 before 10.0.6 improperly neutralizes special elements used in an SQL command allows for authenticated administrative users to trigger SQL Injection. This issue affects JPlatform before 10.0.6 and a PatchPlugin release 10.0.6 was issued 2023-02-06. | |
| Title | Jalios JPlatform 10 SP6 < 10.0.6 Record Chooser SQL Injection | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2025-04-07T21:35:31.322Z
Updated: 2025-11-04T22:18:35.802Z
Reserved: 2025-01-31T18:32:39.809Z
Link: CVE-2025-0942
Updated: 2025-04-08T14:27:53.195Z
Status : Awaiting Analysis
Published: 2025-04-07T22:15:16.020
Modified: 2025-11-04T23:15:34.037
Link: CVE-2025-0942
No data.