CVE-2025-30604

CVSS 3.1 Score 7.6 of 10 (high)

Details

Published Mar 24, 2025
Updated: Mar 27, 2025
CWE ID 89

Summary

CVE-2025-30604 is a newly disclosed SQL Injection vulnerability affecting the JiangQie Official Website Mini Program, from an undefined version up to 1.8.2. The issue arises due to the improper neutralization of special elements used in SQL commands. Maliciously crafted user input can bypass input validations, enabling attackers to execute arbitrary SQL statements, potentially leading to unauthorized data access or manipulation. This vulnerability poses a significant risk to the confidentiality and integrity of data processed by the affected system.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share