CVE-2026-75979
xianrendzw EasyReport SQL Preview Endpoint DesignerController.java previewSqlText special elements in template engine
CVSS Score
6.3
EPSS Score
0.0%
EPSS Percentile
0th
A vulnerability was found in xianrendzw EasyReport up to 2.0.17.0522_Beta. Affected is the function execSqlText/previewSqlText of the file DesignerController.java of the component SQL Preview Endpoint. The manipulation of the argument sqlText results in improper neutralization of special elements used in a template engine. The attack can be executed remotely. The exploit has been made public and could be used. The project was informed of the problem early through an issue report but has not responded yet.
| CWE | CWE-1336 CWE-791 |
| Vendor | xianrendzw |
| Product | easyreport |
| Published | Aug 19, 2026 |
Stay Ahead of the Next One
Get instant alerts for xianrendzw easyreport
Be the first to know when new medium vulnerabilities affecting xianrendzw easyreport are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Affected Versions
xianrendzw / EasyReport
2.0.17.0522_Beta
References
Credits
๐ Ana10gy (VulDB User) VulDB CNA Team