Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
dataease dataease vulnerabilities and exploits
(subscribe to this query)
8.1
CVSSv3
CVE-2023-32310
DataEase is an open source data visualization and analysis tool. The API interface for DataEase delete dashboard and delete system messages is vulnerable to insecure direct object references (IDOR). This could result in a user deleting another user's dashboard or messages or...
Dataease Dataease
7.5
CVSSv3
CVE-2023-40771
SQL injection vulnerability in DataEase v.1.18.9 allows a remote malicious user to obtain sensitive information via a crafted string outside of the blacklist function.
Dataease Dataease 1.18.9
7.5
CVSSv3
CVE-2021-38239
SQL Injection vulnerability in dataease prior to 1.2.0, allows malicious users to gain sensitive information via the orders parameter to /api/sys_msg/list/1/10.
Dataease Dataease
6.5
CVSSv3
CVE-2023-35164
DataEase is an open source data visualization analysis tool to analyze data and gain insight into business trends. In affected versions a missing authorization check allows unauthorized users to manipulate a dashboard created by the administrator. This vulnerability has been fixe...
Dataease Dataease
6.5
CVSSv3
CVE-2023-35168
DataEase is an open source data visualization analysis tool to analyze data and gain insight into business trends. Affected versions of DataEase has a privilege bypass vulnerability where ordinary users can gain access to the user database. Exposed information includes md5 hashes...
Dataease Dataease
6.5
CVSSv3
CVE-2022-34112
An access control issue in the component /api/plugin/uninstall Dataease v1.11.1 allows malicious users to arbitrarily uninstall the plugin, a right normally reserved for the administrator.
Dataease Project Dataease 1.11.1
6.1
CVSSv3
CVE-2023-28435
Dataease is an open source data visualization and analysis tool. The permissions for the file upload interface is not checked so users who are not logged in can upload directly to the background. The file type also goes unchecked, users could upload any type of file. These vulner...
Dataease Dataease
5.4
CVSSv3
CVE-2023-37257
DataEase is an open source data visualization analysis tool. Prior to version 1.18.9, the DataEase panel and dataset have a stored cross-site scripting vulnerability. The vulnerability has been fixed in v1.18.9. There are no known workarounds.
Dataease Dataease
5.4
CVSSv3
CVE-2023-25807
DataEase is an open source data visualization and analysis tool. When saving a dashboard on the DataEase platform saved data can be modified and store malicious code. This vulnerability can lead to the execution of malicious code stored by the attacker on the server side when the...
Dataease Dataease
5.3
CVSSv3
CVE-2023-40183
DataEase is an open source data visualization and analysis tool. Prior to version 1.18.11, DataEase has a vulnerability that allows an malicious user to to obtain user cookies. The program only uses the `ImageIO.read()` method to determine whether the file is an image file or not...
Dataease Dataease
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
cross-site scripting
CVE-2024-5158
XML external entity
CVE-2024-4262
CVE-2024-2036
CVE-2024-4985
CVE-2024-21791
remote attackers
CVE-2023-43208
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
NEXT »