Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Dataease Subscribe
Filtered by product Dataease
Total 4 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-25807 1 Dataease 1 Dataease 2023-03-07 N/A 5.4 MEDIUM
DataEase is an open source data visualization and analysis tool. When saving a dashboard on the DataEase platform saved data can be modified and store malicious code. This vulnerability can lead to the execution of malicious code stored by the attacker on the server side when the user accesses the dashboard. The vulnerability has been fixed in version 1.18.3.
CVE-2021-38239 1 Dataease 1 Dataease 2023-02-22 N/A 7.5 HIGH
SQL Injection vulnerability in dataease before 1.2.0, allows attackers to gain sensitive information via the orders parameter to /api/sys_msg/list/1/10.
CVE-2022-23331 1 Dataease 1 Dataease 2022-10-05 6.5 MEDIUM 8.8 HIGH
In DataEase v1.6.1, an authenticated user can gain unauthorized access to all user information and can change the administrator password.
CVE-2022-34113 1 Dataease 1 Dataease 2022-07-30 N/A 9.8 CRITICAL
An issue in the component /api/plugin/upload of Dataease v1.11.1 allows attackers to execute arbitrary code via a crafted plugin.