{"id":"CVE-2025-71428","summary":"Jivejdon through 5.0 SQL Injection via username in userListAction","details":"Jivejdon through 5.0 contains a sql injection vulnerability in AccountDaoSql.getAccountByNameLike() that allows authenticated administrators to inject SQL via the username parameter. Attackers with the Admin role can submit crafted input to /admin/user/userListAction to read database contents, including other accounts' password hashes.","modified":"2026-10-10T07:06:59.713317574Z","published":"2026-10-08T21:51:27.411Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/71xxx/CVE-2025-71428.json","cna_assigner":"VulnCheck","cwe_ids":["CWE-89"]},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/71xxx/CVE-2025-71428.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-71428"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/jivejdon-through-5.0-sql-injection-via-username-in-userlistaction"},{"type":"REPORT","url":"https://github.com/banq/jivejdon/issues/24"},{"type":"REPORT","url":"https://github.com/banq/jivejdon/issues/28"},{"type":"PACKAGE","url":"https://github.com/banq/jivejdon"},{"type":"ARTICLE","url":"https://github.com/banq/jivejdon/blob/ee67a65e65228644a71c8317d7e34deea50f95ef/src/main/java/com/jdon/jivejdon/infrastructure/repository/dao/sql/AccountDaoSql.java#L329-L335"},{"type":"ARTICLE","url":"https://github.com/banq/jivejdon/blob/ee67a65e65228644a71c8317d7e34deea50f95ef/src/main/java/com/jdon/jivejdon/presentation/action/admin/UserListAction.java#L13-L24"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/banq/jivejdon","events":[{"introduced":"0"},{"fixed":"910fafbfa718d0a2be6bb034fa02bcbb580bd731"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"last_affected":"5.0"},{"fixed":"5.0"}],"source":["AFFECTED_FIELD","DESCRIPTION"]}}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-71428.json","vanir_signatures":[{"id":"CVE-2025-71428-10a379ab","signature_type":"Function","signature_version":"v1","source":"https://github.com/banq/jivejdon/commit/910fafbfa718d0a2be6bb034fa02bcbb580bd731","target":{"file":"src/com/jdon/jivejdon/manager/mapreduce/ThreadApprovedNewList.java","function":"init"},"deprecated":false,"digest":{"function_hash":"7978373696710798170237061069043931066","length":200}},{"id":"CVE-2025-71428-4ff44e2f","signature_type":"Line","signature_version":"v1","source":"https://github.com/banq/jivejdon/commit/910fafbfa718d0a2be6bb034fa02bcbb580bd731","target":{"file":"src/com/jdon/jivejdon/manager/mapreduce/ThreadApprovedNewList.java"},"deprecated":false,"digest":{"line_hashes":["333860100309000275166928495311066973273","30374915342250970483952060235316732239","81414220211742601704501984076563483847","244416318735342282021764486528743115723","167518763580457859731317481743166481880","271811835294668748424500623578188102863","204948462349554106346462956643280388044","97713261130110039020207586332188831138","309120669949091627681488697821745157699","122748421947153433519081177395231259875","274218177332917631892721971919088235599","41599629172191896058670402327105764117"],"threshold":0.9}},{"signature_type":"Function","signature_version":"v1","source":"https://github.com/banq/jivejdon/commit/910fafbfa718d0a2be6bb034fa02bcbb580bd731","target":{"file":"src/com/jdon/jivejdon/model/query/specification/ApprovedListSpec.java","function":"isGoodBlog"},"deprecated":false,"digest":{"function_hash":"59108126195409344060918265431689748972","length":137},"id":"CVE-2025-71428-93c70820"},{"deprecated":false,"digest":{"threshold":0.9,"line_hashes":["185872278007795743557176473001778055140","59525279059624323695607473526051408613","83836500981196697398857103665689467409","121042032624974575198768221417924276931","14004420241609524477760040696659733821","263304077165190376358226209903951123852","49024321835583048676978449252886730798","100467887348313484870724408666892608408"]},"id":"CVE-2025-71428-a326d684","signature_type":"Line","signature_version":"v1","source":"https://github.com/banq/jivejdon/commit/910fafbfa718d0a2be6bb034fa02bcbb580bd731","target":{"file":"src/com/jdon/jivejdon/model/query/specification/ApprovedListSpec.java"}},{"id":"CVE-2025-71428-c28eb86c","signature_type":"Function","signature_version":"v1","source":"https://github.com/banq/jivejdon/commit/910fafbfa718d0a2be6bb034fa02bcbb580bd731","target":{"function":"start","file":"src/com/jdon/jivejdon/manager/mapreduce/ThreadApprovedNewList.java"},"deprecated":false,"digest":{"function_hash":"147664211641395977390983720950410247303","length":197}},{"target":{"function":"isExcelledDiscuss","file":"src/com/jdon/jivejdon/model/query/specification/ApprovedListSpec.java"},"deprecated":false,"digest":{"length":122,"function_hash":"162596087330417603063677428201438723389"},"id":"CVE-2025-71428-d0745307","signature_type":"Function","signature_version":"v1","source":"https://github.com/banq/jivejdon/commit/910fafbfa718d0a2be6bb034fa02bcbb580bd731"},{"signature_version":"v1","source":"https://github.com/banq/jivejdon/commit/910fafbfa718d0a2be6bb034fa02bcbb580bd731","target":{"file":"src/com/jdon/jivejdon/manager/mapreduce/ThreadApprovedNewList.java","function":"run"},"deprecated":false,"digest":{"length":37,"function_hash":"208972022311035733844886350694903749572"},"id":"CVE-2025-71428-fd0b7e4d","signature_type":"Function"}],"vanir_signatures_modified":"2026-10-10T07:06:59Z"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"}]}