CVE-2025-0558

Source
https://cve.org/CVERecord?id=CVE-2025-0558
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-0558.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-0558
Published
2025-01-18T13:00:08Z
Modified
2026-08-27T03:57:00Z
Severity
  • 5.3 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N CVSS Calculator
Summary
TDuckCloud tduck-platform QueryProThemeRequest.java QueryProThemeRequest sql injection
Details

A vulnerability classified as critical was found in TDuckCloud tduck-platform up to 4.0. This vulnerability affects the function QueryProThemeRequest of the file src/main/java/com/tduck/cloud/form/request/QueryProThemeRequest.java. The manipulation of the argument color leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

Database specific
{
    "cna_assigner": "VulDB",
    "cwe_ids": [
        "CWE-74",
        "CWE-89"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/0xxx/CVE-2025-0558.json",
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "introduced": "4.0"
                },
                {
                    "last_affected": "4.0"
                }
            ],
            "source": "AFFECTED_FIELD"
        }
    ]
}
References

Affected packages

Git / github.com/TDuckCloud/tduck-survey-form

Affected ranges

Type
GIT
Repo
https://github.com/TDuckCloud/tduck-survey-form
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last Affected
Database specific
Show details
{
    "cpe": "cpe:2.3:a:tduckcloud:tduck-platform:*:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "4.0"
        }
    ],
    "source": "CPE_RANGE"
}

Affected versions

v0.*
v0.0.1-beta
v2.*
v2.1.0
v4.*
v4.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-0558.json"