DataEase is an open source data visualization and analysis tool. The API interface for DataEase delete dashboard and delete system messages is vulner…
DataEase is an open source data visualization analysis tool. In Dataease users are normally allowed to modify data and the data sources are expected …
Dataease is an open source data visualization and analysis tool. The blacklist for SQL injection protection is missing entries. This vulnerability ha…
Dataease is an open source data visualization and analysis tool. The permissions for the file upload interface is not checked so users who are not lo…
DataEase is an open source data visualization and analysis tool. When saving a dashboard on the DataEase platform saved data can be modified and stor…
SQL Injection vulnerability in dataease before 1.2.0, allows attackers to gain sensitive information via the orders parameter to /api/sys_msg/list/1/…
Dataease is an open source data visualization analysis tool. Dataease prior to 1.15.2 has a deserialization vulnerability. In Dataease, the Mysql dat…
An issue in the component /api/plugin/upload of Dataease v1.11.1 allows attackers to execute arbitrary code via a crafted plugin.
DataEase v1.11.1 was discovered to contain a arbitrary file write vulnerability via the parameter dataSourceId.
Dataease v1.11.1 was discovered to contain a SQL injection vulnerability via the parameter dataSourceId.
An access control issue in the component /api/plugin/uninstall Dataease v1.11.1 allows attackers to arbitrarily uninstall the plugin, a right normall…
In DataEase v1.6.1, an authenticated user can gain unauthorized access to all user information and can change the administrator password.