CVE-2025-3318
CVSS 3.1 Score 6.3 of 10 (medium)
Details
Summary
CVE-2025-3318 is a critical vulnerability affecting the company-financial-management system of Kenj_Frog 肯尼基蛙, version 1.0. The issue lies within the ShangpinleixingController.java file, specifically the function page. A sql injection vulnerability is present, allowing attackers to manipulate arguments and inject malicious SQL code remotely. The exploit for this vulnerability has been disclosed to the public, increasing the risk of attacks. Kenj_Frog uses rolling releases for continual delivery, making it unclear which releases are impacted and which have been updated.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.