CVE-2025-0942

Severity CVSS v4.0:
Pending analysis
Type:
CWE-89 SQL Injection
Publication date:
07/04/2025
Last modified:
08/04/2025

Description

The DB chooser functionality in Jalios JPlatform 10 SP6 before 10.0.6 improperly neutralizes special elements used in an SQL command allows for unauthenticated users to trigger SQL Injection.<br /> <br /> This issue affects JPlatform before 10.0.6 and a PatchPlugin release 10.0.6 was issued 2023-02-06.