Impact
A vulnerability exists in EasyReport's DataSourceController.add function. By manipulating the queryerClass argument, a remote attacker can bypass intended access controls, potentially executing arbitrary queries or achieving broader system privileges. This flaw stems from improper handling of input, allowing unauthorized operations that contravene expected permissions.
Affected Systems
The flaw affects xianrendzw EasyReport versions up to 2.0.17.0522_Beta. The component impacted is QueryerFactory's DataSourceController.java. Users running any unpatched release of this product are susceptible.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate risk, and the attack vector is remote, relying on crafted input to the add endpoint. No public exploitation has been confirmed, and the vulnerability is not listed in the CISA KEV catalog. Nonetheless, the exploit has been disclosed and could be used by malicious actors when the application is exposed to network traffic.
OpenCVE Enrichment