PT-2025-23671 · Dataease · Dataease

Le1Afinderph0Ebusfinder

·

Published

2025-06-03

·

Updated

2026-04-27

·

CVE-2025-49002

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions DataEase versions prior to 2.10.10
Description DataEase is an open source business intelligence and data visualization tool. A flaw exists in a previous patch that allows it to be bypassed through case insensitivity because the prohibited terms INIT and RUNSCRIPT are not handled regardless of case, potentially leading to remote code execution via SQL injection bypass.
Recommendations Update to version 2.10.10.

Exploit

Fix

RCE

Authentication Bypass by Spoofing

Weakness Enumeration

Related Identifiers

CVE-2025-49002
GHSA-999M-JV2P-5H34
GHSA-H7HJ-4J78-CVC7

Affected Products

Dataease