Description
Dataease v1.11.1 was discovered to contain a SQL injection vulnerability via the parameter dataSourceId.
Remediation
References
https://github.com/dataease/dataease/issues/2430
Related Vulnerabilities
CVE-2022-31150 Vulnerability in npm package undici
CVE-2021-41117 Vulnerability in npm package keypair
CVE-2022-2422 Vulnerability in npm package feathers-sequelize
CVE-2022-0613 Vulnerability in npm package urijs
CVE-2023-35155 Vulnerability in maven package org.xwiki.platform:xwiki-platform-sharepage-api