PT-2026-56247 · Dataease · Dataease
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
DataEase versions prior to 2.10.24
Description
The '/de2api/datasetData/previewSql' endpoint lacks the mandatory
@DePermit permission validation annotation. This allows any authenticated user to set the datasourceId variable to -1, granting unauthorized access to the built-in engine database to execute arbitrary SQL statements and read sensitive core data.Recommendations
Update to version 2.10.24.
Restrict access to the '/de2api/datasetData/previewSql' endpoint as a temporary mitigation.
Exploit
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Dataease