CVE-2023-40771: SQL Injection
Published Sep 1, 2023
·Updated
SQL injection vulnerability in DataEase v.1.18.9 allows a remote attacker to obtain sensitive information via a crafted string outside of the blacklist function.
Affected Software
2 affected components
maven/io.dataease:dataease-plugin-common<=1.18.9
Dataease DataEase=1.18.9
Event History
Sep 1, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Advisory Published
06:30 PM
Frequently Asked Questions
1
What is CVE-2023-40771?
CVE-2023-40771 is a SQL injection vulnerability in DataEase v.1.18.9 that allows a remote attacker to obtain sensitive information.
2
How does CVE-2023-40771 impact DataEase v.1.18.9?
CVE-2023-40771 allows a remote attacker to exploit a SQL injection vulnerability in DataEase v.1.18.9 and obtain sensitive information.
3
What is the severity of CVE-2023-40771?
CVE-2023-40771 has a severity rating of 7.5 (high).
4
What software versions are affected by CVE-2023-40771?
DataEase v.1.18.9 is affected by CVE-2023-40771.
5
How can I fix the SQL injection vulnerability in DataEase v.1.18.9?
To fix the SQL injection vulnerability in DataEase v.1.18.9, update to a version that addresses the issue or apply the recommended patches.