← Πίσω στην αναζήτηση CVE

CVE-2026-9524

EasyReport

Περιγραφή

A flaw has been found in xianrendzw EasyReport up to 2.0.17.0522_Beta. Affected by this issue is the function execute of the component REST Endpoint. Executing a manipulation of the argument reportParams can lead to sql injection. The attack can be launched remotely. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS 6.3EPSS 0.246%Κίνδυνος 0.64
Προβολή πηγής
Δημοσίευση
2026-05-26 04:16:27
Επηρεαζόμενες εκδόσεις
<=2.0.17.0522_Beta
Τύπος
Package
Τελευταία τροποποίηση
2026-07-23 11:10:00
Διάνυσμα
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L