PT-2026-51205 · Zhilink · Adp Application Developer Platform
CVSS v2.0
6.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
zhilink ADP Application Developer Platform version 1.0.0
Description
A remote deserialization issue exists in the 'testConnection' endpoint. Manipulation of the
jdbcUrl argument allows for this attack. Deserialization is a process where data is converted back into an object, which can be exploited to execute unauthorized code if the input is not properly validated.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
RCE
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Adp Application Developer Platform