CVE-2026-2094: Flowring|Docpedia - SQL Injection
Docpedia developed by Flowring has a SQL Injection vulnerability, allowing authenticated remote attackers to inject arbitrary SQL commands to read, modify, and delete database contents.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2026-2094?
CVE-2026-2094 is considered a critical SQL Injection vulnerability due to its potential to allow authenticated attackers to manipulate the database.
How do I fix CVE-2026-2094?
To fix CVE-2026-2094, ensure that the application uses prepared statements or parameterized queries to prevent SQL injection.
Who is affected by CVE-2026-2094?
CVE-2026-2094 affects users of Flowring Docpedia, where the SQL injection vulnerability can be exploited by authenticated attackers.
What are the potential impacts of CVE-2026-2094?
The potential impacts of CVE-2026-2094 include unauthorized reading, modifying, or deleting of database contents, leading to data breaches and loss of integrity.
Is user authentication sufficient to protect against CVE-2026-2094?
No, user authentication alone is not sufficient as the vulnerability targets authenticated users to execute arbitrary SQL commands.