Impact
A flaw in xianrendzw EasyReport allows an attacker to send arbitrary text to the previewSqlText endpoint. The input is not properly neutralized before being processed by the template engine, creating a template injection vulnerability that can lead to code execution. The weakness is classified as CWE‑1336 and CWE‑791 and provides a direct route for malicious payloads to be evaluated by the server.
Affected Systems
The issue exists in EasyReport versions up to 2.0.17.0522_Beta, including all builds carrying that identifier. Only the xianrendzw EasyReport product is affected.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. The EPSS is not available and the vulnerability is not listed in CISA KEV. The CVE description notes that the attack can be executed remotely and that the exploit has been made public, but it does not explicitly state whether authentication is required for exploitation. Because the input does not provide details on authentication or access requirements, the exact attack surface cannot be determined from the provided information. Until a vendor patch is available, the risk persists.
OpenCVE Enrichment