SQL Injection Vulnerability in Furion .NET Framework
CVE-2026-108569

5.3MEDIUM

Key Information:

Vendor

Furion

Vendor
CVE Published:
11 October 2026

What is CVE-2026-108569?

A vulnerability exists in the Furion .NET Framework, specifically in the String.Replace function found in the StringRenderExtensions.cs file. This flaw allows for SQL injection through improper handling of the argument Name, enabling remote attackers to manipulate SQL queries. The exploit is publicly available and poses a serious risk to vulnerable applications. Despite early notification, the vendor has not responded to reports about this critical issue.

Affected Version(s)

.NET Framework 4.9.9.0

.NET Framework 4.9.9.1

.NET Framework 4.9.9.2

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

BlackSpdier (VulDB User)
VulDB CNA Team
.