CVE-2026-75979: xianrendzw EasyReport SQL Preview Endpoint DesignerController.java previewSqlText special elements in template engine
A vulnerability was found in xianrendzw EasyReport up to 2.0.17.0522Beta. Affected is the function execSqlText/previewSqlText of the file DesignerController.java of the component SQL Preview Endpoint. The manipulation of the argument sqlText results in improper neutralization of special elements used in a template engine. The attack can be executed remotely. The exploit has been made public and could be used. The project was informed of the problem early through an issue report but has not responded yet.
Affected Software
Event History
Frequently Asked Questions
Which deployments are affected?
xianrendzw EasyReport versions up to and including 2.0.17.0522_Beta are affected, specifically the SQL Preview Endpoint implemented by the execSqlText/previewSqlText functions in DesignerController.java.
What access does an attacker need?
The issue is remotely exploitable and requires low privileges. No user interaction is required, but the attacker must be able to manipulate the sqlText argument submitted to the affected endpoint.
Is public exploitation information available?
Yes. An exploit has been made public and could be used.
Is a vendor fix available?
The provided information does not identify a fixed release. It states that the project was notified early through an issue report but had not responded.