Description
An issue in the component /api/plugin/upload of Dataease v1.11.1 allows attackers to execute arbitrary code via a crafted plugin.
Remediation
References
https://github.com/dataease/dataease/issues/2431
Related Vulnerabilities
CVE-2022-36077 Vulnerability in maven package org.webjars.npm:electron
CVE-2022-44730 Vulnerability in maven package org.apache.xmlgraphics:batik-script
CVE-2020-8127 Vulnerability in npm package reveal.js
CVE-2021-4260 Vulnerability in npm package oils
CVE-2022-23458 Vulnerability in maven package org.webjars.npm:tui-grid