CVE-2022-23331: High severity dataease vulnerability
Published Feb 8, 2022
·Updated
In DataEase v1.6.1, an authenticated user can gain unauthorized access to all user information and can change the administrator password.
Affected Software
1 affected component
Dataease DataEase=1.6.1
Event History
Feb 8, 2022
CVE Published
via MITRE·12:29 PM
Data Sourced
via MITRE·12:29 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2022-23331.
2
What is the severity of CVE-2022-23331?
The severity of CVE-2022-23331 is high with a CVSS score of 8.8.
3
What is affected by CVE-2022-23331?
DataEase v1.6.1 is affected by CVE-2022-23331.
4
How can an authenticated user gain unauthorized access in DataEase v1.6.1?
An authenticated user can gain unauthorized access to all user information and can change the administrator password in DataEase v1.6.1.
5
Is there a fix available for CVE-2022-23331?
At the moment, there is no specific fix available for CVE-2022-23331. It is recommended to keep the system up to date with the latest patches and security updates.