CVE-2025-3318

CVSS 3.1 Score 6.3 of 10 (medium)

Details

Published Apr 6, 2025
Updated: Apr 8, 2025
CWE ID 74
CWE ID 89

Summary

CVE-2025-3318 is a critical vulnerability affecting the company-financial-management system of Kenj_Frog 肯尼基蛙, version 1.0. The issue lies within the ShangpinleixingController.java file, specifically the function page. A sql injection vulnerability is present, allowing attackers to manipulate arguments and inject malicious SQL code remotely. The exploit for this vulnerability has been disclosed to the public, increasing the risk of attacks. Kenj_Frog uses rolling releases for continual delivery, making it unclear which releases are impacted and which have been updated.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share