CVE-2026-75979 | xianrendzw EasyReport up to 2.0.17.0522_Beta SQL Preview Endpoint DesignerController.java execSqlText/previewSqlText sqlText special elements in template engine (Issue 82)

SecurityVulns

A vulnerability categorized as critical has been discovered in xianrendzw EasyReport up to 2.0.17.0522_Beta. Affected is the function execSqlText/previewSqlText of the file DesignerController.java of the component SQL Preview Endpoint. The manipulation of the argument sqlText results in improper neutralization of special elements used in a template engine.

This vulnerability is identified as CVE-2026-75979. The attack can be executed remotely. Additionally, an exploit exists.

The project was informed of the problem early through an issue report but has not responded yet.VulDB Recent EntriesRead More