CVE-2023-37258: DataEase has a SQL injection vulnerability that can bypass blacklists
Published Jul 25, 2023
·Updated
DataEase is an open source data visualization analysis tool. Prior to version 1.18.9, DataEase has a SQL injection vulnerability that can bypass blacklists. The vulnerability has been fixed in v1.18.9. There are no known workarounds.
Affected Software
1 affected component
Dataease DataEase<1.18.9
Event History
Jul 25, 2023
CVE Published
via MITRE·07:36 PM
Data Sourced
via MITRE·07:36 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2023-37258?
CVE-2023-37258 is a SQL injection vulnerability in DataEase prior to version 1.18.9.
2
How severe is the CVE-2023-37258 vulnerability?
The CVE-2023-37258 vulnerability has a severity level of 9.8 (critical).
3
What is affected by CVE-2023-37258?
DataEase versions prior to 1.18.9 are affected by CVE-2023-37258.
4
Is there a fix for CVE-2023-37258?
Yes, the vulnerability has been fixed in version 1.18.9 of DataEase.
5
Are there any workarounds for CVE-2023-37258?
No, there are no known workarounds for CVE-2023-37258.