CVE-2025-13251
- EPSS 0.04%
- Veröffentlicht 16.11.2025 13:15:43
- Zuletzt bearbeitet 20.11.2025 20:38:29
A flaw has been found in WeiYe-Jing datax-web up to 2.1.2. Affected is an unknown function. Executing manipulation can lead to sql injection. The attack may be launched remotely. The exploit has been published and may be used.
CVE-2025-13250
- EPSS 0.06%
- Veröffentlicht 16.11.2025 12:15:44
- Zuletzt bearbeitet 20.11.2025 20:46:55
A vulnerability was detected in WeiYe-Jing datax-web up to 2.1.2. This impacts the function remove/update/pause/start/triggerJob of the component Job Handler. Performing manipulation results in improper access controls. The attack may be initiated re...
CVE-2024-12358
- EPSS 3.85%
- Veröffentlicht 09.12.2024 05:15:07
- Zuletzt bearbeitet 10.12.2024 23:34:20
A vulnerability was found in WeiYe-Jing datax-web 2.1.1. It has been classified as critical. This affects an unknown part of the file /api/job/add/. The manipulation of the argument glueSource leads to os command injection. It is possible to initiate...
CVE-2023-7116
- EPSS 53.81%
- Veröffentlicht 27.12.2023 16:15:13
- Zuletzt bearbeitet 21.11.2024 08:45:18
A vulnerability, which was classified as critical, has been found in WeiYe-Jing datax-web 2.1.2. Affected by this issue is some unknown functionality of the file /api/log/killJob of the component HTTP POST Request Handler. The manipulation of the arg...
CVE-2022-46478
- EPSS 0.71%
- Veröffentlicht 13.01.2023 01:15:10
- Zuletzt bearbeitet 07.04.2025 19:15:44
The RPC interface in datax-web v1.0.0 and v2.0.0 to v2.1.2 contains no permission checks by default which allows attackers to execute arbitrary commands via crafted Hessian serialized data.