Executive brief
A security vulnerability exists in the zhilink ADP Application Developer Platform, a tool used for building and managing software applications. An attacker can exploit this flaw to execute unauthorized commands or gain control over the system by sending a specially crafted database connection string. This could lead to data theft, service disruption, or unauthorized access to internal development resources.
Technical details
A deserialization vulnerability (CWE-502) exists in the 'testConnection' endpoint of zhilink ADP Application Developer Platform version 1.0.0. The issue stems from improper validation of the 'jdbcUrl' argument, which allows an attacker to provide a malicious JDBC URL that triggers the deserialization of untrusted data. This attack can be performed remotely by an authenticated user with low privileges (PR:L). Successful exploitation could lead to remote code execution (RCE) or unauthorized access to the underlying server. Public exploit code is reportedly available, and the vendor has not yet provided a patch or response.
Affected products
- zhilink (智互联) ADP Application Developer Platform (应用开发者平台) 1.0.0
Timeline
- 2026-06-21: disclosed: Vulnerability published via VulDB/NVD