CVE-2025-28198
CVSS 3.1 Score 5.9 of 10 (medium)
Details
Published Apr 15, 2025
Updated: Apr 22, 2025
CWE ID 89
Summary
CVE-2025-28198 is a SQL injection vulnerability affecting Hitout car sale version 1.0. The issue lies within the StoreController.java component and allows remote attackers to gain unauthorized access to sensitive information by manipulating the orderBy parameter. This flaw poses a serious risk, enabling unauthorized querying of databases and potential data theft. The vulnerability should be addressed promptly to prevent potential attacks.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.