Impact
A flaw was discovered in xianrendzw EasyReport up to version 2.0.17.0522_Beta in the execute function of a REST endpoint. Manipulating the argument reportParams can lead to a SQL injection attack that may be launched remotely, allowing an attacker to read or modify the underlying database.
Affected Systems
The affected product is xianrendzw EasyReport, specifically all releases up to and including 2.0.17.0522_Beta. No other versions or variants were listed as vulnerable.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate to high risk. EPSS is not available and the vulnerability is not listed in CISA KEV, suggesting limited widespread exploitation so far. The attack requires remote access to the REST endpoint, and a successful injection could compromise data confidentiality or integrity, depending on database privileges.
OpenCVE Enrichment