PT-2026-22545 · Unknown · Dataease Sqlbot
Vuldb
+1
·
Published
2026-03-02
·
Updated
2026-03-05
·
CVE-2025-15597
CVSS v2.0
6.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Dataease SQLBot versions up to 1.4.0
Description
A security issue has been identified in Dataease SQLBot. This issue relates to improper access controls due to manipulation of an unknown function within the file
backend/apps/system/api/assistant.py of the API Endpoint component. The attack can be launched remotely. Multiple API endpoints are affected. The exploit is publicly available.Recommendations
Upgrade to version 1.5.0 to resolve this issue.
Exploit
Fix
Incorrect Privilege Assignment
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Dataease Sqlbot