PT-2026-60272 · Dataease · Dataease

CVE-2026-45320

·

Published

2026-07-15

·

Updated

2026-07-15

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions DataEase versions prior to 2.10.23
Description Authenticated users with dashboard view permissions can perform SQL injection against integrated datasources. The issue occurs because dashboard SQL variables, such as ${deptId}, are processed by the transFilter() function in SqlparserUtils. For operators other than in and between, the final branch of this function returns raw user input, which is then spliced into the dashboard SQL via the replace() function in SubstitutedSql.
Recommendations Update to version 2.10.23.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-45320
GHSA-8VP9-9HX4-6458

Affected Products

Dataease