rebuild v3.9.0 through v3.9.3 has a SQL injection vulnerability in /admin/admin-cli/exec component.
References
Link | Resource |
---|---|
https://gist.github.com/LTLTLXEY/c34dc785fc24f4cbb026e2ef3d7660c4 | Third Party Advisory |
https://github.com/getrebuild/rebuild/issues/866 | Exploit Issue Tracking |
Configurations
History
23 Jun 2025, 18:07
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:ruifang-tech:rebuild:*:*:*:*:*:*:*:* | |
First Time |
Ruifang-tech rebuild
Ruifang-tech |
|
References | () https://gist.github.com/LTLTLXEY/c34dc785fc24f4cbb026e2ef3d7660c4 - Third Party Advisory | |
References | () https://github.com/getrebuild/rebuild/issues/866 - Exploit, Issue Tracking |
14 May 2025, 14:15
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.8 |
CWE | CWE-89 |
13 May 2025, 16:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-05-13 16:15
Updated : 2025-06-23 18:07
NVD link : CVE-2025-28056
Mitre link : CVE-2025-28056
CVE.ORG link : CVE-2025-28056
JSON object : View
Products Affected
ruifang-tech
- rebuild
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')