CVE-2025-29085
Vipshop Saturn Console Vulnerable to SQL Injection via ClusterKey Component
Record summary
EIP currently links 1 Nuclei template to CVE-2025-29085.
Description
SQL injection vulnerability in vipshop Saturn v.3.5.1 and before allows a remote attacker to execute arbitrary code via /console/dashboard/executorCount?zkClusterKey component.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Jun 9, 2025 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 3, 2025 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
SaturnBrowse vipshop / Saturn | VulnCheck | Version data not supplied | |
com.vip.saturn:saturn-consoleBrowse Maven / com.vip.saturn:saturn-console | GitHub Advisory | Through 3.5.1 | affected |
Nuclei templates
1ProjectDiscoveryCRITICALVipshop Saturn Console <= 3.5.1 - SQL Injection via ClusterKey ComponentCVSS 9.8
SQL injection vulnerability in vipshop Saturn v.3.5.1 and before allows a remote attacker to execute arbitrary code via /console/dashboard/executorCount?zkClusterKey component.
Impact
Unauthenticated attackers can execute arbitrary SQL queries through the zkClusterKey parameter, potentially extracting sensitive database information and compromising Saturn Console.
Remediation
Upgrade to Vipshop Saturn version 3.5.2 or later that properly sanitizes SQL input parameters.
Source: ProjectDiscovery