'; } else{ echo ''; } echo '
|
|
|||
| Rule General Information |
|---|
| Release Date: | 2026-01-14 | |
| Rule Name: | FineReport export excel SQL Injection Vulnerability | |
| Severity: | ||
| CVE ID: | ||
| Rule Protection Details |
|---|
| Description: | FanRuan is a company that provides enterprise-class business intelligence (BI) solutions, the company's main product is FineReport, a powerful and flexible report design and presentation tool. The /export/excel interface in FanRuan (FineReport) reporting software has a SQL injection vulnerability. Attackers can craft malicious SQL statements to write a WebShell to the server, thereby achieving remote code execution. | |
| Impact: | An attacker can inject arbitrary sql commands to view or change the database of the target by exploiting the vulnerability successfully. | |
| Affected OS: | Windows, Linux, Others | |
| Reference: | ||
| Solutions |
|---|
| Please refer to announcements or patches release by the vendor: https://help.fanruan.com/finereport/doc-view-4833.html |