Description
A flaw has been found in xianrendzw EasyReport up to 2.0.17.0522_Beta. Affected by this issue is the function execute of the component REST Endpoint. Executing a manipulation of the argument reportParams can lead to sql injection. The attack can be launched remotely. The vendor was contacted early about this disclosure but did not respond in any way.
Published: 2026-05-26
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw was discovered in xianrendzw EasyReport up to version 2.0.17.0522_Beta in the execute function of a REST endpoint. Manipulating the argument reportParams can lead to a SQL injection attack that may be launched remotely, allowing an attacker to read or modify the underlying database.

Affected Systems

The affected product is xianrendzw EasyReport, specifically all releases up to and including 2.0.17.0522_Beta. No other versions or variants were listed as vulnerable.

Risk and Exploitability

The CVSS score of 5.3 indicates a moderate to high risk. EPSS is not available and the vulnerability is not listed in CISA KEV, suggesting limited widespread exploitation so far. The attack requires remote access to the REST endpoint, and a successful injection could compromise data confidentiality or integrity, depending on database privileges.

Generated by OpenCVE AI on May 26, 2026 at 04:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Verify whether your deployment is running EasyReport version 2.0.17.0522_Beta or an earlier release and whether the vulnerable REST endpoint is publicly reachable.
  • Contact the vendor and request a patch or formal fix; if a fix is not available, block or restrict access to the execute endpoint so that only trusted internal users can invoke it.
  • Apply input‑validation or parameterized query controls on the reportParams field to neutralize any embedded SQL payloads.
  • Monitor database logs for anomalous queries and restrict the database user privileges of the EasyReport application to the minimum required for normal operation.

Generated by OpenCVE AI on May 26, 2026 at 04:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 26 May 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 26 May 2026 03:30:00 +0000

Type Values Removed Values Added
Description A flaw has been found in xianrendzw EasyReport up to 2.0.17.0522_Beta. Affected by this issue is the function execute of the component REST Endpoint. Executing a manipulation of the argument reportParams can lead to sql injection. The attack can be launched remotely. The vendor was contacted early about this disclosure but did not respond in any way.
Title xianrendzw EasyReport REST Endpoint execute sql injection
First Time appeared Xianrendzw
Xianrendzw easyreport
Weaknesses CWE-74
CWE-89
CPEs cpe:2.3:a:xianrendzw:easyreport:*:*:*:*:*:*:*:*
Vendors & Products Xianrendzw
Xianrendzw easyreport
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P/E:ND/RL:ND/RC:UR'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:X/RL:X/RC:R'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:X/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X'}


Subscriptions

Xianrendzw Easyreport
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-05-26T15:14:24.036Z

Reserved: 2026-05-25T19:27:34.135Z

Link: CVE-2026-9524

cve-icon Vulnrichment

Updated: 2026-05-26T15:14:19.221Z

cve-icon NVD

Status : Received

Published: 2026-05-26T04:16:27.617

Modified: 2026-05-26T04:16:27.617

Link: CVE-2026-9524

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-26T12:59:41Z

Weaknesses