Impact
The vulnerability lies in the String.Replace method of the StringRenderExtensions.cs file within the Furion .NET Framework. Manipulating the Name argument allows an attacker to inject arbitrary SQL, which can be executed by the application. This flaw is a classic injection issue categorized as CWE-74 and CWE-89, and it results in remote SQL injection when the application processes user‑supplied input.
Affected Systems
Any deployment of Furion .NET Framework version 4.9.9.92 or earlier is affected. No specific product or sub‑component beyond the framework itself is listed.
Risk and Exploitability
The CVSS base score of 5.3 indicates moderate severity. EPSS is not available, and the vulnerability is not listed in CISA's KEV catalog. Because the flaw permits remote exploitation and public exploits are available, the risk is significant for applications that expose the templating or rendering functions to external users. The likely attack vector is an attacker supplying the Name parameter to the Replace call, which then propagates unsanitized input into a SQL statement, potentially leading to data exfiltration or modification.
OpenCVE Enrichment