CVE-2025-0942

CVSS 3.1 Score 8.6 of 10 (high)

Details

Published Apr 7, 2025
Updated: Apr 8, 2025
CWE ID 89

Summary

CVE-2025-0942 is a vulnerability affecting the DB chooser functionality in Jalios JPlatform 10 SP6. Unauthenticated users can exploit this issue by improperly neutralizing special elements used in SQL commands, resulting in SQL Injection. This vulnerability, if exploited, could lead to unauthorized access or data theft. JPlatform versions before 10.0.6 are impacted and a patch (PatchPlugin release 10.0.6) was released on 2023-02-06 to mitigate this issue.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share