CVE-2025-7888: TDuckCloud tduck-platform UserFormDataMapper.java UserFormDataMapper sql injection
A vulnerability was found in TDuckCloud tduck-platform 5.1 and classified as critical. This issue affects the function UserFormDataMapper of the file src/main/java/com/tduck/cloud/form/mapper/UserFormDataMapper.java. The manipulation of the argument formKey leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-7888?
CVE-2025-7888 is classified as a critical vulnerability.
How do I fix CVE-2025-7888?
To fix CVE-2025-7888, update TDuckCloud tduck-platform to the latest version that addresses this SQL injection issue.
What software is affected by CVE-2025-7888?
The vulnerability CVE-2025-7888 affects TDuckCloud tduck-platform version 5.1.
What type of vulnerability is CVE-2025-7888?
CVE-2025-7888 is an SQL injection vulnerability found in the UserFormDataMapper function.
What consequences can result from CVE-2025-7888?
Exploitation of CVE-2025-7888 can allow attackers to manipulate database queries, leading to unauthorized access or data loss.