CVE-2022-25517 is a critical SQL injection vulnerability affecting MyBatis Plus v3.4.3, specifically within the Column parameter of /core/conditions/AbstractWrapper.java. This vulnerability carries a CVSS score of 9.8, indicating a severe risk with potential for complete compromise of confidentiality, integrity, and availability. While the vendor asserts the reported SQL execution is intended behavior, its high FAUCET Risk Score of 92/100 and significant community discussion (10 mentions) highlight its perceived danger. There is currently no evidence of active exploitation, and no public exploit code is available in Metasploit, Nuclei, or ExploitDB.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
3.4.3CPE matchmatch criteria | cpe:2.3:a:baomidou:mybatis-plus:3.4.3:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.