CVE-2025-5386
Last modified
CVE-2025-5386 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. A vulnerability was found in JeeWMS up to 20250504. It has been rated as critical. EPSS estimates a 0.27% chance of exploitation in the next 30 days.
Description
A vulnerability was found in JeeWMS up to 20250504. It has been rated as critical. This issue affects the function transEditor of the file /cgformTransController.do?transEditor. The manipulation leads to sql injection. The attack may be initiated remotely. This product does not use versioning. This is why information about affected and unaffected releases are unavailable.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Huayi-Tec | Jeewms | <= 2025-05-04 |
References
- https://gitee.com/erzhongxmu/JEEWMS/issues/IC5FNVIssue Tracking
- https://vuldb.com/?ctiid.310679Permissions Required, VDB Entry
- https://vuldb.com/?id.310679Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-5386?
How severe is CVE-2025-5386?
How do I fix CVE-2025-5386?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-53854A reflected cross-site scripting (xss) vulnerability exists …5.4
- CVE-2025-53855An out-of-bounds write vulnerability exists in the XML parse…7.8
- CVE-2025-53856When a virtual server, network address translation (NAT) obj…8.7
- CVE-2025-53857Mattermost Confluence Plugin version <1.5.0 fails to check t…3.7
- CVE-2025-53858ChatLuck contains a cross-site scripting vulnerability in Ch…5.4
- CVE-2025-53859NGINX Open Source and NGINX Plus have a vulnerability in the…6.3
- CVE-2025-53860A vulnerability exists in F5OS-A software that allows a high…4.1
- CVE-2025-53861A flaw was found in Ansible. Sensitive cookies without secur…3.1
- CVE-2025-53862A flaw was found in Ansible. Three API endpoints are accessi…3.5
- CVE-2025-53864Connect2id Nimbus JOSE + JWT 10.0.x before 10.0.2 and 9.37.x…5.8
- CVE-2025-53865In Roundup before 2.5.0, XSS can occur via interaction betwe…6.4
- CVE-2025-53867Island Lake WebBatch before 2025C allows Remote Code Executi…9.8
Are you affected by CVE-2025-5386?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
