PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-71428 banq CVE debrief

CVE-2025-71428 Jivejdon SQL Injection Vulnerability. Jivejdon through 5.0 contains a SQL injection vulnerability in AccountDaoSql.getAccountByNameLike() that allows authenticated administrators to inject SQL via the username parameter in the /admin/user/userListAction endpoint. This could lead to unauthorized database access and data exposure. Administrators and developers should assess exposure and prioritize remediation. The vulnerability has a CVSS score of 6.9 and is considered Medium severity.

Vendor
banq
Product
jivejdon
CVSS
MEDIUM 6.9
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-08
Original CVE updated
2026-10-08
Advisory published
2026-10-08
Advisory updated
2026-10-08

Who should care

Administrators and developers responsible for Jivejdon application security, database administrators, and security teams should assess exposure and prioritize remediation. They should review and restrict access to the /admin/user/userListAction endpoint, validate and sanitize user input, and monitor database activity for suspicious queries. Additionally, they should consider implementing compensating controls, such as Web Application Firewalls (WAFs), and

Why it matters

CVE-2025-71428 is a SQL injection vulnerability in Jivejdon through 5.0 that allows authenticated administrators to inject SQL via the username parameter. Defenders should prioritize remediation and verify exposure, as this vulnerability could lead to unauthorized database access and data exposure.

  • Potential unauthorized database access and data exposure
  • Possible disruption of authentication and authorization mechanisms
  • Required validation and sanitization of user input to prevent SQL injection
  • Need for monitoring database activity for suspicious queries

Technical summary

The Jivejdon application through version 5.0 contains a SQL injection vulnerability in the AccountDaoSql.getAccountByNameLike() method. This method allows authenticated administrators to inject SQL via the username parameter in the /admin/user/userListAction endpoint, potentially leading to unauthorized database access. The vulnerability is caused by inadequate input validation and sanitization. Attackers with the Admin role can submit crafted input to read database contents, including other accounts' password hashes. The vulnerability has a CVSS score of 6.9 and is considered Medium severity.

Defensive priority

Medium priority for authentication and database administrators

Recommended defensive actions

  • Review and restrict access to the /admin/user/userListAction endpoint
  • Validate and sanitize user input to prevent SQL injection
  • Monitor database activity for suspicious queries
  • Update to a version of Jivejdon that addresses this vulnerability, if available
  • Perform a thorough review of database logs for signs of exploitation
  • Implement additional security measures such as Web Application Firewalls (WAFs)
  • Conduct regular security audits to identify similar vulnerabilities

Evidence notes

The CVE record and source item provide details on the SQL injection vulnerability in Jivejdon through 5.0. The vulnerability is in the AccountDaoSql.getAccountByNameLike() method, which allows authenticated administrators to inject SQL via the username parameter in the /admin/user/userListAction endpoint.

Sources and references

Verified primary and authoritative sources

  • CVE-2025-71428 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-71428

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-71428 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-71428

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Jivejdon through 5.0 SQL Injection via username in userListAction

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2025/71xxx/CVE-2025-71428.json

    cve_program_cvelist_v5

  • Source reference

    Unverified legacy reference

    URL: https://github.com/banq/jivejdon/issues/28

    Supplemental source - issue-tracking

  • Source reference

    Unverified legacy reference

    URL: https://github.com/banq/jivejdon

    Supplemental source - product

  • Source reference

    Unverified legacy reference

    URL: https://github.com/banq/jivejdon/issues/24

    Supplemental source - issue-tracking

  • Source reference

    Unverified legacy reference

    URL: https://github.com/banq/jivejdon/blob/ee67a65e65228644a71c8317d7e34deea50f95ef/src/main/java/com/jdon/jivejdon/infrastructure/repository/dao/sql/AccountDaoSql.java

    Supplemental source - technical-description

  • Source reference

    Unverified legacy reference

    URL: https://github.com/banq/jivejdon/blob/ee67a65e65228644a71c8317d7e34deea50f95ef/src/main/java/com/jdon/jivejdon/presentation/action/admin/UserListAction.java

    Supplemental source - technical-description

  • Source reference

    Unverified legacy reference

    URL: https://www.vulncheck.com/advisories/jivejdon-through-5.0-sql-injection-via-username-in-userlistaction

    Supplemental source - third-party-advisory

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.