Impact
A vulnerability in the RainyGao DocSys project, specifically in the BaseController.createDBForMysql method of the Database Management module, allows an attacker to inject arbitrary SQL by manipulating the unvalidated `url` argument. The flaw is a classic SQL injection (CWE‑89), enabling remote execution of malicious SQL statements against the MySQL database, which can compromise data confidentiality, integrity, and potentially availability.
Affected Systems
All instances of RainyGao DocSys up to and including version 2.02.85 are affected. The vulnerability resides in the BaseController class within the Database Management component. No official vendor patch is currently available, and the upstream project has not released a fix.
Risk and Exploitability
The CVSS score of 6.9 classifies the vulnerability as moderate severity, and the EPSS score is not available. The vulnerability is not listed in the CISA KEV catalog, but a public exploit has already been published. Attackers can target the affected endpoint remotely—likely via the web interface or API that accepts the `url` parameter—by sending a crafted request that triggers the injection. Given the lack of an official fix and the publicly available exploit, the risk remains significant until a proper patch or mitigation is applied.
OpenCVE Enrichment