CVE-2025-15493

A flaw has been found in RainyGao DocSys up to 2.02.36. The impacted element is an unknown function of the file src/com/DocSystem/mapping/ReposAuthMapper.xml. Executing a manipulation of the argument searchWord can lead to sql injection. It is possible to launch the attack remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Configurations

Configuration 1 (hide)

cpe:2.3:a:docsys_project:docsys:*:*:*:*:*:*:*:*

History

29 Apr 2026, 01:00

Type Values Removed Values Added
Summary
  • (es) Se ha encontrado una vulnerabilidad en RainyGao DocSys hasta la versión 2.02.36. El elemento afectado es una función desconocida del archivo src/com/DocSystem/mapping/ReposAuthMapper.xml. La ejecución de una manipulación del argumento searchWord puede conducir a una inyección SQL. Es posible lanzar el ataque remotamente. El exploit ha sido publicado y puede ser utilizado. Se contactó al proveedor con antelación sobre esta divulgación, pero no respondió de ninguna manera.

22 Jan 2026, 15:42

Type Values Removed Values Added
CPE cpe:2.3:a:docsys_project:docsys:*:*:*:*:*:*:*:*
First Time Docsys Project
Docsys Project docsys
References () https://github.com/xkalami-Tta0/CVE/blob/main/DocSys/sql%E6%B3%A8%E5%85%A52.md - () https://github.com/xkalami-Tta0/CVE/blob/main/DocSys/sql%E6%B3%A8%E5%85%A52.md - Exploit, Third Party Advisory
References () https://github.com/xkalami-Tta0/CVE/blob/main/DocSys/sql%E6%B3%A8%E5%85%A52.md#vulnerability-analysis-and-reproduction%E6%BC%8F%E6%B4%9E%E5%88%86%E6%9E%90%E5%A4%8D%E7%8E%B0 - () https://github.com/xkalami-Tta0/CVE/blob/main/DocSys/sql%E6%B3%A8%E5%85%A52.md#vulnerability-analysis-and-reproduction%E6%BC%8F%E6%B4%9E%E5%88%86%E6%9E%90%E5%A4%8D%E7%8E%B0 - Exploit, Third Party Advisory
References () https://vuldb.com/?ctiid.340271 - () https://vuldb.com/?ctiid.340271 - Permissions Required, VDB Entry
References () https://vuldb.com/?id.340271 - () https://vuldb.com/?id.340271 - Third Party Advisory, VDB Entry
References () https://vuldb.com/?submit.725374 - () https://vuldb.com/?submit.725374 - Third Party Advisory, VDB Entry

09 Jan 2026, 19:16

Type Values Removed Values Added
References () https://github.com/xkalami-Tta0/CVE/blob/main/DocSys/sql%E6%B3%A8%E5%85%A52.md - () https://github.com/xkalami-Tta0/CVE/blob/main/DocSys/sql%E6%B3%A8%E5%85%A52.md -
References () https://github.com/xkalami-Tta0/CVE/blob/main/DocSys/sql%E6%B3%A8%E5%85%A52.md#vulnerability-analysis-and-reproduction%E6%BC%8F%E6%B4%9E%E5%88%86%E6%9E%90%E5%A4%8D%E7%8E%B0 - () https://github.com/xkalami-Tta0/CVE/blob/main/DocSys/sql%E6%B3%A8%E5%85%A52.md#vulnerability-analysis-and-reproduction%E6%BC%8F%E6%B4%9E%E5%88%86%E6%9E%90%E5%A4%8D%E7%8E%B0 -

09 Jan 2026, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-09 17:15

Updated : 2026-04-29 01:00


NVD link : CVE-2025-15493

Mitre link : CVE-2025-15493

CVE.ORG link : CVE-2025-15493


JSON object : View

Products Affected

docsys_project

  • docsys
CWE
CWE-74

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')