---
id: CVE-2025-71428
title: >-
  Jivejdon through 5.0 contains a sql injection vulnerability in
  AccountDaoSql.getAccountByNameLike() that allows authenticated administrators
  to inject SQL via the username parameter
summary: >-
  Jivejdon through 5.0 contains a sql injection vulnerability in
  AccountDaoSql.getAccountByNameLike() that allows authenticated administrators
  to inject SQL via the username parameter. Attackers with the Admin role can
  submit crafted input…
severity: medium
cvss: 4.9
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-89
published: '2026-10-08'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T22:17:26.033'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-71428'
references:
  - url: 'https://github.com/banq/jivejdon'
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/banq/jivejdon/blob/ee67a65e65228644a71c8317d7e34deea50f95ef/src/main/java/com/jdon/jivejdon/infrastructure/repository/dao/sql/AccountDaoSql.java#L329-L335
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/banq/jivejdon/blob/ee67a65e65228644a71c8317d7e34deea50f95ef/src/main/java/com/jdon/jivejdon/presentation/action/admin/UserListAction.java#L13-L24
    label: disclosure@vulncheck.com
  - url: 'https://github.com/banq/jivejdon/issues/24'
    label: disclosure@vulncheck.com
  - url: 'https://github.com/banq/jivejdon/issues/28'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/jivejdon-through-5.0-sql-injection-via-username-in-userlistaction
    label: disclosure@vulncheck.com
tags:
  - nvd
ingestedAt: '2026-10-08T23:16:47.386Z'
---

## Overview

Jivejdon through 5.0 contains a sql injection vulnerability in AccountDaoSql.getAccountByNameLike() that allows authenticated administrators to inject SQL via the username parameter. Attackers with the Admin role can submit crafted input to /admin/user/userListAction to read database contents, including other accounts' password hashes.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
