CVE-2021-38239: SQL Injection
Published Feb 15, 2023
·Updated
SQL Injection vulnerability in dataease before 1.2.0, allows attackers to gain sensitive information via the orders parameter to /api/sysmsg/list/1/10.
Affected Software
1 affected component
Dataease DataEase<1.2.0
Event History
Feb 15, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·10:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2021-38239.
2
What is the severity of CVE-2021-38239?
The severity of CVE-2021-38239 is high with a score of 7.5.
3
Which software versions are affected by CVE-2021-38239?
Versions before 1.2.0 of Dataease are affected by CVE-2021-38239.
4
What is the impact of CVE-2021-38239?
CVE-2021-38239 allows attackers to gain sensitive information.
5
Is there a fix available for CVE-2021-38239?
Yes, updating to version 1.2.0 of Dataease fixes the vulnerability.