PT-2026-56252 · Dataease · Dataease

·

CVE-2026-55635

·

Published

2026-07-07

·

Updated

2026-07-09

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions DataEase versions prior to 2.10.24
Description An authenticated user capable of creating or modifying chart definitions, or submitting chart data requests containing quota filters, can inject SQL into queries executed against configured datasources. This occurs because chart quota and Y-axis filters embed attacker-controlled filter values directly into generated SQL within the getYWheres() function of Quota2SQLObj without applying the necessary SQL literal validation and escaping used by other filter paths.
Recommendations Update to version 2.10.24.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-55635
GHSA-P758-RX6V-HC8G

Affected Products

Dataease