Record summary

EIP currently links 1 Nuclei template to CVE-2025-29085.

Description

SQL injection vulnerability in vipshop Saturn v.3.5.1 and before allows a remote attacker to execute arbitrary code via /console/dashboard/executorCount?zkClusterKey component.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Jun 9, 2025 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableYes
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 3, 2025 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied
GitHub AdvisoryThrough 3.5.1affected

Nuclei templates

1
ProjectDiscoveryCRITICALVipshop Saturn Console <= 3.5.1 - SQL Injection via ClusterKey ComponentCVSS 9.8

SQL injection vulnerability in vipshop Saturn v.3.5.1 and before allows a remote attacker to execute arbitrary code via /console/dashboard/executorCount?zkClusterKey component.

Impact

Unauthenticated attackers can execute arbitrary SQL queries through the zkClusterKey parameter, potentially extracting sensitive database information and compromising Saturn Console.

Remediation

Upgrade to Vipshop Saturn version 3.5.2 or later that properly sanitizes SQL input parameters.

WeaknessesCWE-89
Authorsiamnoooob, rootxharsh, pdresearch
Template tagscvecve2025vipshopsqlivkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Source: ProjectDiscovery

References

3