CVE-2026-105158 | RainyGao DocSys up to 2.02.85 Database Management BaseController.java BaseController.createDBForMysql url sql injection (IK8NEU)
A vulnerability described as critical has been identified in RainyGao DocSys up to 2.02.85. The impacted element is the function BaseController.createDBForMysql of the file BaseController.java of the component Database Management. The manipulation of the argument url results in sql injection.
This vulnerability is identified as CVE-2026-105158. The attack can be executed remotely. Additionally, an exploit exists.
The project was informed of the problem early through an issue report but has not responded yet.VulDB Recent EntriesRead More