PT-2026-60275 · Dataease · Dataease
CVE-2026-45533
·
Published
2026-07-15
·
Updated
2026-07-15
CVSS v4.0
8.3
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H |
Name of the Vulnerable Software and Affected Versions
DataEase versions prior to 2.10.23
Description
An issue exists in the bulk delete API endpoint where path traversal sequences, such as
../, can be accepted. This allows attacker-controlled identifiers to be passed to the delete() function within ExportCenterManage, enabling the recursive deletion of arbitrary directories on the server during export task cleanup. Path traversal is a technique used to access files or directories outside the intended folder by using special character sequences.Recommendations
Update to version 2.10.23.
Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Dataease