Sceawere
Vulnerability Detail
CVE-2026-105158UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
SQL Injection in DocSys
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.3
- Creation Date
- 5h ago
- Vendor
- RainyGao
- Product
- DocSys
- Attack Type
- SQL Injection
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
A vulnerability was detected in RainyGao DocSys up to 2.02.85. The impacted element is the function BaseController.createDBForMysql of the file BaseController.java of the component Database Management. The manipulation of the argument url results in sql injection. The attack can be executed remotely. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.3",
"pubDate": "2026-10-04T15:16:31.150Z",
"pubdate": "2026-10-04T15:16:31.150Z",
"executiveSummary": "A critical SQL injection vulnerability has been identified in RainyGao DocSys, affecting versions up to 2.02.85.\nThe vulnerability resides within the Database Management component, specifically in the BaseController.createDBForMysql function.\nThis flaw allows remote, unauthenticated attackers to manipulate the 'url' argument, potentially leading to unauthorized execution of arbitrary SQL commands against the backend database.\nThe vulnerability poses a severe risk, as successful exploitation could result in unauthorized data exfiltration, modification, or destruction of database contents.\nGiven that the exploit is currently public and the vendor has not responded to initial disclosures, the risk of exploitation by malicious actors is considered high.",
"technicalDetails": "The vulnerability is an Improper Neutralization of Special Elements used in an SQL Command, commonly known as SQL Injection, located in the Database Management component of RainyGao DocSys.\nThe root cause is identified as the insecure handling of the 'url' argument within the BaseController.createDBForMysql function in BaseController.java.\nThe application fails to properly sanitize or parameterize user-supplied input provided via the 'url' parameter before incorporating it into a database query string.\nThe attack flow initiates with a remote attacker sending a crafted HTTP request containing malicious SQL fragments injected into the 'url' parameter.\nBecause the function processes this input without adequate validation or the use of prepared statements, the database engine interprets the injected malicious characters as executable SQL code rather than literal data.\nThis allows the attacker to bypass standard application logic and interface directly with the database layer.\nBy manipulating the SQL query, an attacker can influence the control flow of the database interaction, enabling operations such as UNION-based data retrieval, blind SQL injection for sensitive data extraction, or potentially modifications to existing database entries if the application's database user possesses sufficient privileges.\nThe exploitation is feasible remotely, requiring no prior authentication to the application, which significantly expands the attack surface.\nThe vulnerability affects all versions of RainyGao DocSys up to and including 2.02.85.\nThe lack of vendor remediation or patch availability means the underlying code remains inherently susceptible to this injection vector when the affected component is exposed to untrusted input."
}