Description
An access control issue in the component /api/plugin/uninstall Dataease v1.11.1 allows attackers to arbitrarily uninstall the plugin, a right normally reserved for the administrator.
Remediation
References
https://github.com/dataease/dataease/issues/2429
Related Vulnerabilities
CVE-2020-8123 Vulnerability in npm package strapi
CVE-2020-28278 Vulnerability in maven package org.webjars.npm:shvl
CVE-2021-27515 Vulnerability in maven package org.webjars.bowergithub.unshiftio:url-parse
CVE-2018-3746 Vulnerability in npm package pdfinfojs
CVE-2022-25646 Vulnerability in npm package x-data-spreadsheet