Dataease

Dataease

57 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.45%
  • Veröffentlicht 25.07.2023 20:15:13
  • Zuletzt bearbeitet 21.11.2024 08:11:19

DataEase is an open source data visualization analysis tool. Prior to version 1.18.9, the DataEase panel and dataset have a stored cross-site scripting vulnerability. The vulnerability has been fixed in v1.18.9. There are no known workarounds.

Exploit
  • EPSS 0.06%
  • Veröffentlicht 26.06.2023 22:15:11
  • Zuletzt bearbeitet 21.11.2024 08:08:04

DataEase is an open source data visualization analysis tool to analyze data and gain insight into business trends. In affected versions a missing authorization check allows unauthorized users to manipulate a dashboard created by the administrator. Th...

Exploit
  • EPSS 0.06%
  • Veröffentlicht 26.06.2023 21:15:09
  • Zuletzt bearbeitet 21.11.2024 08:08:04

DataEase is an open source data visualization analysis tool to analyze data and gain insight into business trends. Affected versions of DataEase has a privilege bypass vulnerability where ordinary users can gain access to the user database. Exposed i...

Exploit
  • EPSS 0.13%
  • Veröffentlicht 26.06.2023 21:15:09
  • Zuletzt bearbeitet 21.11.2024 08:07:18

DataEase is an open source data visualization analysis tool to analyze data and gain insight into business trends. In affected versions Unauthorized users can delete an application erroneously. This vulnerability has been fixed in version 1.18.8. Use...

Exploit
  • EPSS 1.6%
  • Veröffentlicht 01.06.2023 16:15:09
  • Zuletzt bearbeitet 21.11.2024 08:06:18

DataEase is an open source data visualization and analysis tool. Prior to version 1.18.7, a deserialization vulnerability exists in the DataEase datasource, which can be exploited to execute arbitrary code. The vulnerability has been fixed in v1.18.7...

Exploit
  • EPSS 0.15%
  • Veröffentlicht 01.06.2023 16:15:09
  • Zuletzt bearbeitet 21.11.2024 08:03:05

DataEase is an open source data visualization and analysis tool. The API interface for DataEase delete dashboard and delete system messages is vulnerable to insecure direct object references (IDOR). This could result in a user deleting another user's...

Exploit
  • EPSS 2.26%
  • Veröffentlicht 28.03.2023 21:15:11
  • Zuletzt bearbeitet 21.11.2024 07:55:42

DataEase is an open source data visualization analysis tool. In Dataease users are normally allowed to modify data and the data sources are expected to properly sanitize data. The AWS redshift data source does not provide data sanitization which may ...

Exploit
  • EPSS 0.23%
  • Veröffentlicht 25.03.2023 00:15:08
  • Zuletzt bearbeitet 21.11.2024 07:55:03

Dataease is an open source data visualization and analysis tool. The blacklist for SQL injection protection is missing entries. This vulnerability has been fixed in version 1.18.5. There are no known workarounds.

Exploit
  • EPSS 0.26%
  • Veröffentlicht 24.03.2023 21:15:06
  • Zuletzt bearbeitet 21.11.2024 07:55:03

Dataease is an open source data visualization and analysis tool. The permissions for the file upload interface is not checked so users who are not logged in can upload directly to the background. The file type also goes unchecked, users could upload ...

Exploit
  • EPSS 0.84%
  • Veröffentlicht 28.02.2023 16:15:09
  • Zuletzt bearbeitet 21.11.2024 07:50:14

DataEase is an open source data visualization and analysis tool. When saving a dashboard on the DataEase platform saved data can be modified and store malicious code. This vulnerability can lead to the execution of malicious code stored by the attack...