First published: Wed Feb 15 2023(Updated: )
SQL Injection vulnerability in dataease before 1.2.0, allows attackers to gain sensitive information via the orders parameter to /api/sys_msg/list/1/10.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Dataease | <1.2.0 | |
<1.2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2021-38239.
The severity of CVE-2021-38239 is high with a score of 7.5.
Versions before 1.2.0 of Dataease are affected by CVE-2021-38239.
CVE-2021-38239 allows attackers to gain sensitive information.
Yes, updating to version 1.2.0 of Dataease fixes the vulnerability.