UReport SQL Injection Vulnerability Allowing Database Information Access and Potential Remote Code Execution

Vulnerability

A SQL injection vulnerability exists in UReport version 2.2.9 within the '/ureport/datasource/previewData' component. This vulnerability allows attackers to execute arbitrary SQL commands, accessing sensitive database information. The issue arises from inadequate filtering and validation of SQL statements, leaving the application open to injection attacks. Exploitation of this vulnerability could also lead to remote code execution, particularly in environments with misconfigured database permissions.

Impact

Exploitation of this vulnerability allows for arbitrary SQL execution, leading to unauthorized access to sensitive database information. Additionally, it could enable remote code execution by writing web shells or escalating privileges through MySQL user-defined functions, depending on the database's permission settings.

Reproduction

To reproduce this vulnerability, upload UReport version 2.2.9 to a server and use the local built-in database. Access the UReport designer interface without authentication. Once the application is running, navigate to the data preview interface. Here, SQL injection can be performed by sending crafted SQL statements through the previewData endpoint. For example, injecting SQL commands to retrieve database information or execute arbitrary SQL could demonstrate the vulnerability.

Added: Jul 16, 2026, 11:15 PM
Updated: Jul 16, 2026, 11:15 PM

Vulnerability Rating

Custom Algorithm
spread
0.8
impact
3.1
exploitability
9.5
remediation
0.0
relevance
9.6
threat
6.4
urgency
2.9
incentive
8.3

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.