CVE-2025-13268

A flaw has been found in Dromara dataCompare up to 1.0.1. The affected element is the function DbConfig of the file src/main/java/com/vince/xq/project/system/dbconfig/service/DbconfigServiceImpl.java of the component JDBC URL Handler. Executing manipulation can lead to injection. The attack can be launched remotely. The exploit has been published and may be used.
Configurations

No configuration.

History

17 Nov 2025, 08:16

Type Values Removed Values Added
New CVE

Information

Published : 2025-11-17 08:16

Updated : 2025-11-18 14:06


NVD link : CVE-2025-13268

Mitre link : CVE-2025-13268

CVE.ORG link : CVE-2025-13268


JSON object : View

Products Affected

No product.

CWE
CWE-74

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

CWE-707

Improper Neutralization