CVE-2025-15492: RainyGao DocSys GroupMemberMapper.xml sql injection
A vulnerability was detected in RainyGao DocSys up to 2.02.36. The affected element is an unknown function of the file src/com/DocSystem/mapping/GroupMemberMapper.xml. Performing a manipulation of the argument searchWord results in sql injection. It is possible to initiate the attack remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-15492?
CVE-2025-15492 has been classified with a high severity due to the risk of SQL injection.
How do I fix CVE-2025-15492?
To fix CVE-2025-15492, upgrade RainyGao DocSys to version 2.02.37 or later.
What type of vulnerability is CVE-2025-15492?
CVE-2025-15492 is a SQL injection vulnerability found in RainyGao DocSys.
Which versions of RainyGao DocSys are affected by CVE-2025-15492?
Versions of RainyGao DocSys up to and including 2.02.36 are affected by CVE-2025-15492.
How can attackers exploit CVE-2025-15492?
Attackers can exploit CVE-2025-15492 by manipulating the searchWord argument in the affected XML file.