CVE-2025-71428: Jivejdon through 5.0 SQL Injection via username in userListAction
Published Oct 8, 2026
·Updated
Jivejdon through 5.0 contains a sql injection vulnerability in AccountDaoSql.getAccountByNameLike() that allows authenticated administrators to inject SQL via the username parameter. Attackers with the Admin role can submit crafted input to /admin/user/userListAction to read database contents, including other accounts' password hashes.
Affected Software
1 affected component
Jivejdon Jivejdon<=5.0
Event History
Oct 8, 2026
CVE Published
via MITRE·09:51 PM
Data Sourced
via MITRE·09:51 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access is required to exploit this issue?
An attacker must be authenticated and hold the Admin role. The vulnerable request is submitted to the /admin/user/userListAction administrative endpoint.
2
What could an attacker obtain through successful exploitation?
An attacker can read database contents through SQL injection, including password hashes for other accounts.