Description
Dataease v1.11.1 was discovered to contain a SQL injection vulnerability via the parameter dataSourceId.
Remediation
References
https://github.com/dataease/dataease/issues/2430
Related Vulnerabilities
CVE-2021-3822 Vulnerability in npm package jsoneditor
CVE-2022-25918 Vulnerability in npm package shescape
CVE-2020-16044 Vulnerability in npm package electron
CVE-2020-25689 Vulnerability in maven package org.wildfly.core:wildfly-protocol
CVE-2022-31070 Vulnerability in npm package @ffdc/nestjs-proxy