PatchSiren cyber security CVE debrief
CVE-2025-71428 banq CVE debrief
CVE-2025-71428 Jivejdon SQL Injection Vulnerability. Jivejdon through 5.0 contains a SQL injection vulnerability in AccountDaoSql.getAccountByNameLike() that allows authenticated administrators to inject SQL via the username parameter in the /admin/user/userListAction endpoint. This could lead to unauthorized database access and data exposure. Administrators and developers should assess exposure and prioritize remediation. The vulnerability has a CVSS score of 6.9 and is considered Medium severity.
- Vendor
- banq
- Product
- jivejdon
- CVSS
- MEDIUM 6.9
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-08
- Original CVE updated
- 2026-10-08
- Advisory published
- 2026-10-08
- Advisory updated
- 2026-10-08
Who should care
Administrators and developers responsible for Jivejdon application security, database administrators, and security teams should assess exposure and prioritize remediation. They should review and restrict access to the /admin/user/userListAction endpoint, validate and sanitize user input, and monitor database activity for suspicious queries. Additionally, they should consider implementing compensating controls, such as Web Application Firewalls (WAFs), and
Why it matters
CVE-2025-71428 is a SQL injection vulnerability in Jivejdon through 5.0 that allows authenticated administrators to inject SQL via the username parameter. Defenders should prioritize remediation and verify exposure, as this vulnerability could lead to unauthorized database access and data exposure.
- Potential unauthorized database access and data exposure
- Possible disruption of authentication and authorization mechanisms
- Required validation and sanitization of user input to prevent SQL injection
- Need for monitoring database activity for suspicious queries
Technical summary
The Jivejdon application through version 5.0 contains a SQL injection vulnerability in the AccountDaoSql.getAccountByNameLike() method. This method allows authenticated administrators to inject SQL via the username parameter in the /admin/user/userListAction endpoint, potentially leading to unauthorized database access. The vulnerability is caused by inadequate input validation and sanitization. Attackers with the Admin role can submit crafted input to read database contents, including other accounts' password hashes. The vulnerability has a CVSS score of 6.9 and is considered Medium severity.
Defensive priority
Medium priority for authentication and database administrators
Recommended defensive actions
- Review and restrict access to the /admin/user/userListAction endpoint
- Validate and sanitize user input to prevent SQL injection
- Monitor database activity for suspicious queries
- Update to a version of Jivejdon that addresses this vulnerability, if available
- Perform a thorough review of database logs for signs of exploitation
- Implement additional security measures such as Web Application Firewalls (WAFs)
- Conduct regular security audits to identify similar vulnerabilities
Evidence notes
The CVE record and source item provide details on the SQL injection vulnerability in Jivejdon through 5.0. The vulnerability is in the AccountDaoSql.getAccountByNameLike() method, which allows authenticated administrators to inject SQL via the username parameter in the /admin/user/userListAction endpoint.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-71428 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-71428
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-71428 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-71428
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Jivejdon through 5.0 SQL Injection via username in userListAction
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2025/71xxx/CVE-2025-71428.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://github.com/banq/jivejdon/issues/28
Supplemental source - issue-tracking
-
Source reference
Unverified legacy reference
URL: https://github.com/banq/jivejdon
Supplemental source - product
-
Source reference
Unverified legacy reference
URL: https://github.com/banq/jivejdon/issues/24
Supplemental source - issue-tracking
-
Source reference
Unverified legacy reference
URL: https://github.com/banq/jivejdon/blob/ee67a65e65228644a71c8317d7e34deea50f95ef/src/main/java/com/jdon/jivejdon/infrastructure/repository/dao/sql/AccountDaoSql.java
Supplemental source - technical-description
-
Source reference
Unverified legacy reference
URL: https://github.com/banq/jivejdon/blob/ee67a65e65228644a71c8317d7e34deea50f95ef/src/main/java/com/jdon/jivejdon/presentation/action/admin/UserListAction.java
Supplemental source - technical-description
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/jivejdon-through-5.0-sql-injection-via-username-in-userlistaction
Supplemental source - third-party-advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.