Description
A vulnerability was detected in RainyGao DocSys up to 2.02.85. The impacted element is the function BaseController.createDBForMysql of the file BaseController.java of the component Database Management. The manipulation of the argument url results in sql injection. The attack can be executed remotely. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet.
Published: 2026-10-04
Score: 6.9 Medium
EPSS: n/a
KEV: No
Impact: Remote SQL Injection
Action: Patch
AI Analysis

Impact

A vulnerability in the RainyGao DocSys project, specifically in the BaseController.createDBForMysql method of the Database Management module, allows an attacker to inject arbitrary SQL by manipulating the unvalidated `url` argument. The flaw is a classic SQL injection (CWE‑89), enabling remote execution of malicious SQL statements against the MySQL database, which can compromise data confidentiality, integrity, and potentially availability.

Affected Systems

All instances of RainyGao DocSys up to and including version 2.02.85 are affected. The vulnerability resides in the BaseController class within the Database Management component. No official vendor patch is currently available, and the upstream project has not released a fix.

Risk and Exploitability

The CVSS score of 6.9 classifies the vulnerability as moderate severity, and the EPSS score is not available. The vulnerability is not listed in the CISA KEV catalog, but a public exploit has already been published. Attackers can target the affected endpoint remotely—likely via the web interface or API that accepts the `url` parameter—by sending a crafted request that triggers the injection. Given the lack of an official fix and the publicly available exploit, the risk remains significant until a proper patch or mitigation is applied.

Generated by OpenCVE AI on October 4, 2026 at 15:50 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply any vendor‑provided patch once available, or contact the developer for a fix.
  • Modify the BaseController.createDBForMysql method to sanitize the `url` input, use parameterized queries, and prevent SQL injection.
  • Restrict access to the endpoint that accepts the `url` parameter by implementing firewall rules or network segmentation to whitelist trusted hosts.

Generated by OpenCVE AI on October 4, 2026 at 15:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 04 Oct 2026 14:30:00 +0000

Type Values Removed Values Added
Description A vulnerability was detected in RainyGao DocSys up to 2.02.85. The impacted element is the function BaseController.createDBForMysql of the file BaseController.java of the component Database Management. The manipulation of the argument url results in sql injection. The attack can be executed remotely. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet.
Title RainyGao DocSys Database Management BaseController.java BaseController.createDBForMysql sql injection
First Time appeared Rainygao
Rainygao docsys
Weaknesses CWE-74
CWE-89
CPEs cpe:2.3:a:rainygao:docsys:*:*:*:*:*:*:*:*
Vendors & Products Rainygao
Rainygao docsys
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:C'}

cvssV3_0

{'score': 7.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:C'}

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:C'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-10-04T13:15:22.742Z

Reserved: 2026-10-03T19:44:25.264Z

Link: CVE-2026-105158

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-04T15:16:31.150

Modified: 2026-10-04T15:16:31.150

Link: CVE-2026-105158

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-04T18:00:13Z

Weaknesses
  • CWE-74

    Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')