Vulnerabilities
Vulnerable Software
Dataease:  >> Dataease  >> 1.18.26  Security Vulnerabilities
DataEase is an open source data visualization analysis tool. Prior to version 2.10.1, there is an XML external entity injection vulnerability in the static resource upload interface of DataEase. An attacker can construct a payload to implement intranet detection and file reading. The vulnerability has been fixed in v2.10.1.
CVSS Score
7.5
EPSS Score
0.002
Published
2024-09-23
DataEase is an open source data visualization analysis tool. Prior to version 2.10.1, an attacker can achieve remote command execution by adding a carefully constructed h2 data source connection string. The vulnerability has been fixed in v2.10.1.
CVSS Score
9.8
EPSS Score
0.168
Published
2024-09-23
DataEase, an open source data visualization and analysis tool, has a database configuration information exposure vulnerability prior to version 2.5.0. Visiting the `/de2api/engine/getEngine;.js` path via a browser reveals that the platform's database configuration is returned. The vulnerability has been fixed in v2.5.0. No known workarounds are available aside from upgrading.
CVSS Score
5.3
EPSS Score
0.921
Published
2024-04-08


Contact Us

Shodan ® - All rights reserved