CVE-2025-0391

CVSS 3.1 Score 6.3 of 10 (medium)

Details

Published Jan 11, 2025
CWE ID 74
CWE ID 89

Summary

CVE-2025-0391 is a critical vulnerability that affects Guangzhou Huayi Intelligent Technology's Jeewms up to version 20241229. The issue lies in the saveOrUpdate function of the file CgFormBuildController.java located in the org/jeecgframework/web/cgform/controller/build directory. An attacker can exploit this vulnerability through sql injection, allowing remote manipulation. The exploit has been made public, increasing the risk of attacks. To mitigate this risk, it is strongly recommended to upgrade to Jeewms version 20250101 as soon as possible.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share