Description
An issue in the component /api/plugin/upload of Dataease v1.11.1 allows attackers to execute arbitrary code via a crafted plugin.
Remediation
References
https://github.com/dataease/dataease/issues/2431
Related Vulnerabilities
CVE-2022-24441 Vulnerability in npm package snyk
CVE-2023-40809 Vulnerability in maven package org.opencrx:opencrx-core-models
CVE-2020-7740 Vulnerability in npm package node-pdf-generator
CVE-2022-0528 Vulnerability in npm package @uppy/companion
CVE-2022-24728 Vulnerability in maven package org.webjars.npm:ckeditor4