CVE-2025-1832

CVSS 3.1 Score 6.3 of 10 (medium)

Details

Published Mar 2, 2025
Updated: Mar 3, 2025
CWE ID 74
CWE ID 89

Summary

CVE-2025-1832 is a critical vulnerability affecting zj1983 zz up to version 2024-8. The function getUserList in the file src/main/java/com/futvan/z/system/zrole/ZroleAction.java is the source of the issue. Manipulation of the roleid argument allows for sql injection attacks, which can be executed remotely. The vulnerability has been publicly disclosed, increasing the risk for exploitation. Regrettably, the vendor was unresponsive to early notifications about this disclosure.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share