CVE-2025-3318: Kenj_Frog 肯尼基蛙 company-financial-management 公司财务管理系统 ShangpinleixingController.java page sql injection
A vulnerability classified as critical was found in KenjFrog 肯尼基蛙 company-financial-management 公司财务管理系统 1.0. Affected by this vulnerability is the function page of the file src/main/java/com/controller/ShangpinleixingController.java. The manipulation of the argument sort leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. This product takes the approach of rolling releases to provide continious delivery. Therefore, version details for affected and updated releases are not available.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-3318?
CVE-2025-3318 is classified as critical due to its potential to lead to SQL injection vulnerabilities.
What software is affected by CVE-2025-3318?
CVE-2025-3318 affects Kenj_Frog company-financial-management version 1.0.
How do I fix CVE-2025-3318?
To fix CVE-2025-3318, input validation and parameterized queries should be implemented in the affected function.
What impact does CVE-2025-3318 have on applications?
CVE-2025-3318 can allow attackers to manipulate database queries, potentially leading to data leakage or unauthorized data access.
Is there a patch for CVE-2025-3318?
Currently, there are no specific patches provided for CVE-2025-3318; a code review and mitigation measures are recommended.