PT-2026-60272 · Dataease · Dataease
CVE-2026-45320
·
Published
2026-07-15
·
Updated
2026-07-15
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
DataEase versions prior to 2.10.23
Description
Authenticated users with dashboard view permissions can perform SQL injection against integrated datasources. The issue occurs because dashboard SQL variables, such as
${deptId}, are processed by the transFilter() function in SqlparserUtils. For operators other than in and between, the final branch of this function returns raw user input, which is then spliced into the dashboard SQL via the replace() function in SubstitutedSql.Recommendations
Update to version 2.10.23.
Exploit
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Dataease