Dataease

Dataease

62 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 91.9%
  • Veröffentlicht 08.04.2024 15:15:07
  • Zuletzt bearbeitet 12.02.2025 17:50:06

DataEase, an open source data visualization and analysis tool, has a database configuration information exposure vulnerability prior to version 2.5.0. Visiting the `/de2api/engine/getEngine;.js` path via a browser reveals that the platform's database...

Exploit
  • EPSS 0.6%
  • Veröffentlicht 29.02.2024 01:44:08
  • Zuletzt bearbeitet 08.01.2025 18:52:16

Dataease is an open source data visualization analysis tool. A deserialization vulnerability exists in the DataEase datasource, which can be exploited to execute arbitrary code. The location of the vulnerability code is `core/core-backend/src/main/ja...

Exploit
  • EPSS 0.1%
  • Veröffentlicht 21.09.2023 15:15:10
  • Zuletzt bearbeitet 21.11.2024 08:18:57

DataEase is an open source data visualization and analysis tool. Prior to version 1.18.11, DataEase has a vulnerability that allows an attacker to to obtain user cookies. The program only uses the `ImageIO.read()` method to determine whether the file...

Exploit
  • EPSS 0.17%
  • Veröffentlicht 01.09.2023 16:15:08
  • Zuletzt bearbeitet 21.11.2024 08:20:06

SQL injection vulnerability in DataEase v.1.18.9 allows a remote attacker to obtain sensitive information via a crafted string outside of the blacklist function.

Exploit
  • EPSS 0.45%
  • Veröffentlicht 25.07.2023 20:15:13
  • Zuletzt bearbeitet 21.11.2024 08:11:19

DataEase is an open source data visualization analysis tool. Prior to version 1.18.9, the DataEase panel and dataset have a stored cross-site scripting vulnerability. The vulnerability has been fixed in v1.18.9. There are no known workarounds.

Exploit
  • EPSS 0.19%
  • Veröffentlicht 25.07.2023 20:15:13
  • Zuletzt bearbeitet 21.11.2024 08:11:19

DataEase is an open source data visualization analysis tool. Prior to version 1.18.9, DataEase has a SQL injection vulnerability that can bypass blacklists. The vulnerability has been fixed in v1.18.9. There are no known workarounds.

Exploit
  • EPSS 0.08%
  • Veröffentlicht 26.06.2023 22:15:11
  • Zuletzt bearbeitet 21.11.2024 08:08:04

DataEase is an open source data visualization analysis tool to analyze data and gain insight into business trends. In affected versions a missing authorization check allows unauthorized users to manipulate a dashboard created by the administrator. Th...

Exploit
  • EPSS 0.07%
  • Veröffentlicht 26.06.2023 21:15:09
  • Zuletzt bearbeitet 21.11.2024 08:08:04

DataEase is an open source data visualization analysis tool to analyze data and gain insight into business trends. Affected versions of DataEase has a privilege bypass vulnerability where ordinary users can gain access to the user database. Exposed i...

Exploit
  • EPSS 0.17%
  • Veröffentlicht 26.06.2023 21:15:09
  • Zuletzt bearbeitet 21.11.2024 08:07:18

DataEase is an open source data visualization analysis tool to analyze data and gain insight into business trends. In affected versions Unauthorized users can delete an application erroneously. This vulnerability has been fixed in version 1.18.8. Use...

Exploit
  • EPSS 2.12%
  • Veröffentlicht 01.06.2023 16:15:09
  • Zuletzt bearbeitet 21.11.2024 08:06:18

DataEase is an open source data visualization and analysis tool. Prior to version 1.18.7, a deserialization vulnerability exists in the DataEase datasource, which can be exploited to execute arbitrary code. The vulnerability has been fixed in v1.18.7...