Metrics
Affected Vendors & Products
Fri, 09 Jan 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 09 Jan 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was detected in RainyGao DocSys up to 2.02.36. The affected element is an unknown function of the file src/com/DocSystem/mapping/GroupMemberMapper.xml. Performing a manipulation of the argument searchWord results in sql injection. It is possible to initiate the attack remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. | |
| Title | RainyGao DocSys GroupMemberMapper.xml sql injection | |
| Weaknesses | CWE-74 CWE-89 |
|
| References |
|
|
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-01-09T18:38:08.299Z
Reserved: 2026-01-09T11:30:38.788Z
Link: CVE-2025-15492
Updated: 2026-01-09T17:49:30.787Z
Status : Received
Published: 2026-01-09T16:16:06.213
Modified: 2026-01-09T19:16:05.753
Link: CVE-2025-15492
No data.
OpenCVE Enrichment
No data.