S4E just found a high-severity finding from ssl sweet32 vulnerability checker
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Apr 7, 2025

CVE-2025-29085 Scanner

CVE-2025-29085 Scanner - SQL Injection vulnerability in Vipshop Saturn Console

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
2.4k
Times Used
continuous scan runs
5.9k
Continuously Checked
assets under CS
1
Vulnerabilities Found
confirmed findings
References
CVECVE-2025-29085
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.

SQL injection vulnerability in vipshop Saturn v.3.5.1 and before allows a remote attacker to execute arbitrary code via /console/dashboard/executorCount?zkClusterKey component.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
n/aby n/a
n/a
Updated Sep 9, 2026View on NVD →
Detail

Vipshop Saturn Console is utilized by companies seeking efficient backend operation management, particularly in e-commerce settings. It allows admins to monitor system performance, manage clusters, and maintain overall system health. Various tech teams within an organization use this console to execute system operations and troubleshoot issues. The console's user-friendly interface and comprehensive feature set make it a favored choice for operational teams. Furthermore, Vipshop Saturn Console seamlessly integrates with other tools within the Vipshop ecosystem, thereby providing a cohesive user experience. Its primary purpose is to simplify complex system administration tasks, enhancing efficiency for backend operations.

SQL injection vulnerabilities arise when an attacker manipulates a standard SQL query by injecting unexpected inputs. This vulnerability allows attackers to interface directly with the database employed by the Vipshop Saturn Console. Through manipulating existing code structures, an attacker can execute unauthorized commands, retrieve data, and even alter database contents. Particularly concerning is the potential for attackers to escalate their privileges, granting them more control than originally permitted. The detected vulnerability particularly affects the zkClusterKey component in version 3.5.1 and earlier, which is designed for executing backend tasks. Addressing such vulnerabilities is crucial to safeguarding data integrity and preventing unauthorized database access.

Technical details reveal that the vulnerability leverages a parameter in the /console/dashboard/executorCount endpoint. Particularly, the zkClusterKey parameter is susceptible to SQL manipulation. By cleverly manipulating inputs, attackers can induce the system to execute unintended SQL commands. As a part of this attack, something as simple as SQL syntax could be used to reveal sensitive database information. A successful attack could expose the queries executed by backend processes, giving insights into database structure and operations. The vulnerability extends to potential privilege escalation, allowing an attacker to perform actions way beyond initial entry point permissions.

If the vulnerability is exploited by malicious actors, there's a significant risk of unauthorized access and control over the database, leading to potential data leaks. Sense of control loss over database functions can disrupt services, mismanage resources, and steal confidential information. SQL Injection vulnerabilities can also lead to financial overhauls, reputational damage, and legal complications for the affected organization. Sensitive customer data could be exposed, affecting customer trust and potentially violating privacy regulations. Attackers could also introduce malicious content into the database, further complicating recovery efforts and system integrity.

REFERENCES

Solution Advice
  • Update Vipshop Saturn Console to the latest version and apply patches that fix the identified vulnerability.
  • Implement parameterized queries and stored procedures to mitigate SQL injection risks.
  • Employ a web application firewall (WAF) to detect and block SQL injection attempts in real time.
  • Regularly audit and monitor database interactions for suspicious activities.
  • Educate development teams on secure coding practices to prevent SQL injection vulnerabilities in future deployments.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2025-29085 Scanner - SQL Injection vulnerability in Vipshop Saturn Console | S4E