Description
Dataease v1.11.1 was discovered to contain a SQL injection vulnerability via the parameter dataSourceId.
Remediation
References
https://github.com/dataease/dataease/issues/2430
Related Vulnerabilities
CVE-2020-28442 Vulnerability in npm package js-data
CVE-2020-8127 Vulnerability in maven package org.webjars.bower:reveal.js
CVE-2020-7682 Vulnerability in npm package marked-tree
CVE-2009-1190 Vulnerability in maven package org.springframework:spring-core
CVE-2023-24057 Vulnerability in maven package org.hl7.fhir.publisher:org.hl7.fhir.publisher.core