Published: 25/03/2023 Updated: 30/03/2023
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9

Vulnerability Summary

Dataease is an open source data visualization and analysis tool. The blacklist for SQL injection protection is missing entries. This vulnerability has been fixed in version 1.18.5. There are no known workarounds.

Most Upvoted Vulmon Research Post

There is no Researcher post for this vulnerability
Would you like to share something about it? Sign up now to share your knowledge with the community.
Vulnerable Product Search on Vulmon Subscribe to Product

dataease dataease

Github Repositories

BugLogger About some of the bug i found, 当流水账记录下发现的bug Index Team Product Vul Type 001 fit2cloud dataease CVE-2023-28437 SQL injection 002 fit2cloud dataease CVE-2023-28435 xss 003 fit2cloud dataease CVE-2023-34463 IDOR 004 fit2cloud dataease CVE-2023-35168 privilege bypass 005 fit2cloud dataease CVE-2023-35164 IDOR