Description
An issue in the component /api/plugin/upload of Dataease v1.11.1 allows attackers to execute arbitrary code via a crafted plugin.
Remediation
References
https://github.com/dataease/dataease/issues/2431
Related Vulnerabilities
CVE-2022-22963 Vulnerability in maven package org.springframework.cloud:spring-cloud-function-core
CVE-2020-28458 Vulnerability in maven package org.webjars.bower:datatables.net
CVE-2017-16098 Vulnerability in npm package charset
CVE-2018-19056 Vulnerability in maven package org.webjars.bower:editor.md
CVE-2021-43138 Vulnerability in maven package org.webjars:async