SQL Injection Vulnerability in RainyGao DocSys Software
CVE-2025-15494
Key Information:
Badges
What is CVE-2025-15494?
A SQL injection vulnerability has been identified in RainyGao's DocSys software up to version 2.02.37. This flaw resides in the UserMapper.xml file, where an attacker could exploit the Username argument to execute arbitrary SQL queries. The vulnerability allows for remote exploitation, potentially compromising data integrity and confidentiality. Despite early notifications to the vendor regarding this issue, no response has been recorded. Immediate action is recommended for users operating affected versions to mitigate potential risks.
Affected Version(s)
DocSys 2.02.0
DocSys 2.02.1
DocSys 2.02.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
