A vulnerability classified as critical has been found in liujianview gymxmjpa 1.0. This affects the function MembertypeDaoImpl of the file src/main/java/com/liujian/gymxmjpa/controller/MembertypeController.java. The manipulation of the argument typeName leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
History

Mon, 05 May 2025 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Liujianview
Liujianview gymxmjpa
CPEs cpe:2.3:a:liujianview:gymxmjpa:1.0:*:*:*:*:*:*:*
Vendors & Products Liujianview
Liujianview gymxmjpa

Mon, 13 Jan 2025 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 13 Jan 2025 02:45:00 +0000

Type Values Removed Values Added
Description A vulnerability classified as critical has been found in liujianview gymxmjpa 1.0. This affects the function MembertypeDaoImpl of the file src/main/java/com/liujian/gymxmjpa/controller/MembertypeController.java. The manipulation of the argument typeName leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Title liujianview gymxmjpa MembertypeController.java MembertypeDaoImpl sql injection
Weaknesses CWE-74
CWE-89
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published: 2025-01-13T02:31:05.066Z

Updated: 2025-01-13T18:01:15.343Z

Reserved: 2025-01-12T18:37:33.411Z

Link: CVE-2025-0409

cve-icon Vulnrichment

Updated: 2025-01-13T18:01:10.965Z

cve-icon NVD

Status : Analyzed

Published: 2025-01-13T03:15:06.667

Modified: 2025-05-05T15:21:08.160

Link: CVE-2025-0409

cve-icon Redhat

No data.