Description
An issue in the component /api/plugin/upload of Dataease v1.11.1 allows attackers to execute arbitrary code via a crafted plugin.
Remediation
References
https://github.com/dataease/dataease/issues/2431
Related Vulnerabilities
CVE-2022-35131 Vulnerability in npm package joplin
CVE-2020-26301 Vulnerability in npm package ssh2
CVE-2021-42697 Vulnerability in maven package com.typesafe.akka:akka-http-core_2.13
CVE-2021-23434 Vulnerability in npm package object-path
CVE-2019-20364 Vulnerability in maven package org.igniterealtime.openfire:xmppserver