CVE-2026-108569: Furion .NET Framework StringRenderExtensions.cs String.Replace sql injection
A vulnerability was identified in Furion .NET Framework up to 4.9.9.92. The impacted element is the function String.Replace of the file framework/Furion/Templates/Extensions/StringRenderExtensions.cs. The manipulation of the argument Name leads to sql injection. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
Which deployments are affected?
Furion .NET Framework versions up to 4.9.9.92 are identified as affected. The vulnerable code is in framework/Furion/Templates/Extensions/StringRenderExtensions.cs.
What access does an attacker need to exploit this?
The vulnerability is remotely exploitable with low attack complexity, but the supplied severity vector indicates that the attacker requires low-level privileges. No user interaction is required.
Is exploit code available?
Yes. The available data states that a public exploit exists and may be used.
What is known about vendor remediation?
The vendor was contacted early about the disclosure but did not respond. The provided data does not identify a fixed version or an official mitigation.
What is the potential impact of successful exploitation?
The severity vector indicates low impact to confidentiality, integrity, and availability. The issue is classified as SQL injection through manipulation of the Name argument.