CVE-2025-4494

HIGH

JAdmin 1.0 - Improper Authentication in Admin Backend Login Function

Title source: llm
STIX 2.1

Description

A vulnerability, which was classified as critical, was found in JAdmin-JAVA JAdmin 1.0. Affected is the function toLogin of the file NoNeedLoginController.java of the component Admin Backend. The manipulation leads to improper authentication. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

References (5)

Core 5
Core References
Third Party Advisory, VDB Entry vdb-entry technical-description
https://vuldb.com/?id.308208
Permissions Required, VDB Entry signature permissions-required
https://vuldb.com/?ctiid.308208
Third Party Advisory, VDB Entry third-party-advisory
https://vuldb.com/?submit.566984
Exploit, Issue Tracking, Third Party Advisory issue-tracking
https://github.com/JAdmin-JAVA/JAdmin/issues/1
Exploit, Issue Tracking, Third Party Advisory exploit issue-tracking
https://github.com/JAdmin-JAVA/JAdmin/issues/1#issue-3012501470

Scores

CVSS v3 7.3
EPSS 0.0060
EPSS Percentile 44.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-287
Status published
Products (1)
jadmin-java/jadmin 1.0
Published May 09, 2025
Tracked Since Feb 18, 2026