huija bicycleSharingServer AdminController.java searchAdminMessageShow sql injection

CVE Details

Basic Information

Title huija bicycleSharingServer AdminController.java searchAdminMessageShow sql injection
Type cve
Published 2025-06-27T02:00:11.675Z
Last Seen

Product Information

Vendor huija
Product bicycleSharingServer
Version 7b8a3ba48ad618604abd4797d2e7cf3b5ac7625a

CVSS Information

Base Score 5.3 (MEDIUM)
Attack Vector CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
Confidentiality Impact
Integrity Impact
Availability Impact

AI Analysis

AI Description A SQL injection vulnerability exists in the searchAdminMessageShow function of the AdminController.java file in huija’s bicycleSharingServer. This vulnerability can be exploited remotely by manipulating the Title argument. The product does not use versioning, so specific affected versions are not available. The exploit has been publicly disclosed.
AI Severity Medium
Vendor huija
Product bicycleSharingServer
Affected Version 7b8a3ba48ad618604abd4797d2e7cf3b5ac7625a

Affected Products

  • huija bicycleSharingServer 7b8a3ba48ad618604abd4797d2e7cf3b5ac7625a

Additional Information

CVE List
CWE List CWE-89, CWE-74
Bulletin Family

Description

A vulnerability classified as critical was found in huija bicycleSharingServer up to 7b8a3ba48ad618604abd4797d2e7cf3b5ac7625a. Affected by this vulnerability is the function searchAdminMessageShow of the file AdminController.java. The manipulation of the argument Title leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. This product does not use versioning. This is why information about affected and unaffected releases are unavailable.

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.