{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/rainygao/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:rainygao:docsys:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.3,"id":"CVE-2026-105158"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["DocSys (\u003c= 2.02.85)"],"_cs_severities":["high"],"_cs_tags":["web-application-vulnerability","sqli","vulnerability-management"],"_cs_type":"advisory","_cs_vendors":["RainyGao"],"content_html":"\u003cp\u003eRainyGao DocSys versions up to 2.02.85 contain a critical SQL injection vulnerability (CVE-2026-105158) located within the Database Management component. The flaw exists in the BaseController.createDBForMysql function within the BaseController.java file. An unauthenticated remote attacker can exploit this vulnerability by manipulating the 'url' argument passed to the function. Successful exploitation allows for the execution of arbitrary SQL commands against the backend database, potentially leading to unauthorized data access, modification, or deletion. The vulnerability has been publicly disclosed and a proof-of-concept exploit may be available. As of the time of reporting, the vendor has not provided a patch for this issue.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability allows unauthenticated remote attackers to perform SQL injection attacks, which could result in full database compromise. Depending on the database configuration, this may lead to complete data exfiltration, unauthorized administrative access, or loss of system integrity.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eMonitor web server logs for HTTP requests directed at the Database Management component that contain common SQL injection patterns in the 'url' argument.\u003c/li\u003e\n\u003cli\u003eImplement strict input validation and parameterization for all user-supplied data, particularly the 'url' parameter within the Database Management module, to mitigate the risk until an official patch is released by the vendor.\u003c/li\u003e\n\u003cli\u003eRestrict network access to the DocSys administration and management interfaces to trusted IP addresses only, reducing the attack surface for remote exploitation.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-04T16:53:43Z","date_published":"2026-10-04T16:53:43Z","id":"https://feed.craftedsignal.io/briefs/2026-10-rainygao-docsys-sqli/","summary":"RainyGao DocSys versions up to 2.02.85 contain a remote SQL injection vulnerability in the Database Management component, allowing unauthenticated attackers to execute arbitrary SQL commands via the url argument.","title":"SQL Injection in RainyGao DocSys","url":"https://feed.craftedsignal.io/briefs/2026-10-rainygao-docsys-sqli/"}],"language":"en","title":"CraftedSignal Threat Feed - RainyGao","version":"https://jsonfeed.org/version/1.1"}