Vulnerabilities
Vulnerable Software
Dataease:  >> Dataease  Security Vulnerabilities
Dataease is an open source data visualization and analysis tool. The permissions for the file upload interface is not checked so users who are not logged in can upload directly to the background. The file type also goes unchecked, users could upload any type of file. These vulnerabilities has been fixed in version 1.18.5.
CVSS Score
6.5
EPSS Score
0.003
Published
2023-03-24
DataEase is an open source data visualization and analysis tool. When saving a dashboard on the DataEase platform saved data can be modified and store malicious code. This vulnerability can lead to the execution of malicious code stored by the attacker on the server side when the user accesses the dashboard. The vulnerability has been fixed in version 1.18.3.
CVSS Score
7.2
EPSS Score
0.006
Published
2023-02-28
SQL Injection vulnerability in dataease before 1.2.0, allows attackers to gain sensitive information via the orders parameter to /api/sys_msg/list/1/10.
CVSS Score
7.5
EPSS Score
0.002
Published
2023-02-15
Dataease is an open source data visualization analysis tool. Dataease prior to 1.15.2 has a deserialization vulnerability. In Dataease, the Mysql data source in the data source function can customize the JDBC connection parameters and the Mysql server target to be connected. In `backend/src/main/java/io/dataease/provider/datasource/JdbcProvider.java`, the `MysqlConfiguration` class does not filter any parameters. If an attacker adds some parameters to a JDBC url and connects to a malicious mysql server, the attacker can trigger the mysql jdbc deserialization vulnerability. Through the deserialization vulnerability, the attacker can execute system commands and obtain server privileges. Version 1.15.2 contains a patch for this issue.
CVSS Score
9.8
EPSS Score
0.001
Published
2022-10-25
An issue in the component /api/plugin/upload of Dataease v1.11.1 allows attackers to execute arbitrary code via a crafted plugin.
CVSS Score
9.8
EPSS Score
0.003
Published
2022-07-22
In DataEase v1.6.1, an authenticated user can gain unauthorized access to all user information and can change the administrator password.
CVSS Score
8.8
EPSS Score
0.005
Published
2022-02-08


Contact Us

Shodan ® - All rights reserved