Impact
The vulnerability is a SQL injection flaw in the sourcePath argument of ModuleController.java within the Move Operations module of xianrendzw EasyReport. By supplying a crafted value, an attacker can cause the application to include untrusted input directly into an SQL statement, allowing arbitrary queries or modifications to the database. The flaw can compromise the confidentiality and integrity of the data stored by the application.
Affected Systems
All installations of EasyReport up to 2.0.17.0522_Beta are affected. Versions released after that milestone that have fixed the unsafe handling of sourcePath are not impacted.
Risk and Exploitability
The flaw is exploitable remotely; an attacker only needs the ability to send requests to the affected endpoint. The publicly disclosed exploit demonstrates that the vulnerability can be used in the wild. With a CVSS score of 5.3, the risk is moderate, and the lack of an EPSS score or KEV listing means there is currently no quantitative data on exploitation frequency. Until the vendor issues an official patch, the threat remains significant.
OpenCVE Enrichment