Skip to content
Threat Feed
high advisory

SQL Injection in RainyGao DocSys

RainyGao DocSys versions up to 2.02.85 contain a remote SQL injection vulnerability in the Database Management component, allowing unauthenticated attackers to execute arbitrary SQL commands via the url argument.

CVE search metadata

CVE search record: CVE-2026-105158. Severity: high. CVSS: 7.3. KEV: no. Product: DocSys (<= 2.02.85). Brief: SQL Injection in RainyGao DocSys. Brief link: https://feed.craftedsignal.io/briefs/2026-10-rainygao-docsys-sqli/

RainyGao DocSys versions up to 2.02.85 contain a critical SQL injection vulnerability (CVE-2026-105158) located within the Database Management component. The flaw exists in the BaseController.createDBForMysql function within the BaseController.java file. An unauthenticated remote attacker can exploit this vulnerability by manipulating the 'url' argument passed to the function. Successful exploitation allows for the execution of arbitrary SQL commands against the backend database, potentially leading to unauthorized data access, modification, or deletion. The vulnerability has been publicly disclosed and a proof-of-concept exploit may be available. As of the time of reporting, the vendor has not provided a patch for this issue.

Impact

The vulnerability allows unauthenticated remote attackers to perform SQL injection attacks, which could result in full database compromise. Depending on the database configuration, this may lead to complete data exfiltration, unauthorized administrative access, or loss of system integrity.

Recommendation

  • Monitor web server logs for HTTP requests directed at the Database Management component that contain common SQL injection patterns in the 'url' argument.
  • Implement strict input validation and parameterization for all user-supplied data, particularly the 'url' parameter within the Database Management module, to mitigate the risk until an official patch is released by the vendor.
  • Restrict network access to the DocSys administration and management interfaces to trusted IP addresses only, reducing the attack surface for remote exploitation.

Immediate actions

Restrict external network access to DocSys Database Management endpoints

IT Operations 24h

Mitigations

Implement WAF rules to block SQL injection payloads targeting the url argument

immediate SOC

CVE-2026-105158