Sceawere
Vulnerability Detail
CVE-2026-108569UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Furion StringRenderExtensions SQL Injection
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.3
- Creation Date
- 4h ago
- Vendor
- Furion
- Product
- .NET Framework
- Attack Type
- SQL Injection
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
A vulnerability was identified in Furion .NET Framework up to 4.9.9.92. The impacted element is the function String.Replace of the file framework/Furion/Templates/Extensions/StringRenderExtensions.cs. The manipulation of the argument Name leads to sql injection. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.3",
"pubDate": "2026-10-11T11:16:58.727Z",
"pubdate": "2026-10-11T11:16:58.727Z",
"executiveSummary": "A critical SQL injection vulnerability exists in the Furion .NET framework, specifically within the String.Replace function located in framework/Furion/Templates/Extensions/StringRenderExtensions.cs.\nThe vulnerability allows remote, unauthenticated attackers to manipulate the 'Name' argument to inject malicious SQL commands into database queries.\nImpact includes unauthorized data access, potential modification or deletion of database contents, and potential compromise of the underlying data store.\nThe vulnerability affects all Furion versions up to 4.9.9.92.\nPublicly available exploit code increases the risk, necessitating immediate attention, especially since the vendor has not responded to vulnerability disclosure.",
"technicalDetails": "The root cause of this vulnerability lies in the improper sanitization and handling of user-supplied input within the String.Replace method in framework/Furion/Templates/Extensions/StringRenderExtensions.cs. The function fails to adequately parameterize or escape input provided via the 'Name' argument before it is utilized in constructing database queries.\nWhen an application utilizes this extension method to render templates or manipulate strings that subsequently interact with a database layer, the injected malicious SQL code is executed with the privileges of the database user configured for the application.\nThe attack flow commences when an attacker provides a crafted string containing SQL syntax to the vulnerable 'Name' argument. Because the application logic trusts this input, it is concatenated directly into the query structure. The database engine interprets the attacker-supplied input as part of the SQL command, allowing for arbitrary query execution.\nAn attacker can leverage this injection point to perform various malicious activities, such as extracting sensitive information from tables, bypassing authentication mechanisms, or executing administrative database commands.\nThe vulnerability is remotely exploitable, requiring no prior authentication or specific privilege level, making it a high-risk vector. The exploit is facilitated by the lack of input validation and the absence of parameterized queries or prepared statements when handling the affected argument.\nGiven that the application interacts with the database directly using unsanitized input from this extension, an attacker can manipulate query logic to return unintended datasets, perform unauthorized data modifications, or potentially gain further system access depending on the database configuration and permissions."
}