CVE-2026-9524

MEDIUM

xianrendzw EasyReport REST Endpoint execute sql injection

Title source: cna
STIX 2.1

Description

A flaw has been found in xianrendzw EasyReport up to 2.0.17.0522_Beta. Affected by this issue is the function execute of the component REST Endpoint. Executing a manipulation of the argument reportParams can lead to sql injection. The attack can be launched remotely. The vendor was contacted early about this disclosure but did not respond in any way.

References (4)

Core 4
Core References
Vdb Entry, Technical Description vdb-entry technical-description
VDB-365543 | xianrendzw EasyReport REST Endpoint execute sql injection
https://vuldb.com/vuln/365543
Signature, Permissions Required signature permissions-required
VDB-365543 | CTI Indicators (IOB, IOC, TTP, IOA)
https://vuldb.com/vuln/365543/cti
Third Party Advisory third-party-advisory
Submit #814567 | xianrendzw EasyReport Releases SQL Injection
https://vuldb.com/submit/814567

Scores

CVSS v3 6.3
EPSS 0.0025
EPSS Percentile 15.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-74 CWE-89
Status published
Products (1)
xianrendzw/EasyReport 2.0.17.0522_Beta
Published May 26, 2026
Tracked Since May 26, 2026