CVE Details
Basic Information
| Title | huija bicycleSharingServer UserServiceImpl.java userDao.selectUserByUserNameLike sql injection |
|---|---|
| Type | cve |
| Published | 2025-06-27T00:00:17.281Z |
| Last Seen |
Product Information
| Vendor | huija |
|---|---|
| Product | bicycleSharingServer |
| Version | 7b8a3ba48ad618604abd4797d2e7cf3b5ac7625a |
CVSS Information
| Base Score | 5.3 (MEDIUM) |
|---|---|
| Attack Vector | CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P |
| Confidentiality Impact | |
| Integrity Impact | |
| Availability Impact |
AI Analysis
| AI Description | A critical SQL injection vulnerability was found in the huija bicycleSharingServer, specifically in the function userDao.selectUserByUserNameLike. This allows remote attackers to inject malicious SQL code by manipulating the Username argument. The exploit is publicly disclosed, making it a significant risk. |
|---|---|
| AI Severity | Medium |
| Vendor | huija |
| Product | bicycleSharingServer |
| Affected Version | 7b8a3ba48ad618604abd4797d2e7cf3b5ac7625a |
Affected Products
- huija bicycleSharingServer 7b8a3ba48ad618604abd4797d2e7cf3b5ac7625a
Additional Information
| CVE List | |
|---|---|
| CWE List | CWE-89, CWE-74 |
| Bulletin Family |
References
Description
A vulnerability, which was classified as critical, has been found in huija bicycleSharingServer up to 7b8a3ba48ad618604abd4797d2e7cf3b5ac7625a. Affected by this issue is the function userDao.selectUserByUserNameLike of the file UserServiceImpl.java. The manipulation of the argument Username leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. This product is using a rolling release to provide continuous delivery. Therefore, no version details for affected nor updated releases are available.