ZeroHour

CVE-2023-28435

PoC ×2
CVSS 3.1
6.1 medium
EPSS
<1%p39
Published
()
Modified
Description

Dataease is an open source data visualization and analysis tool. The permissions for the file upload interface is not checked so users who are not logged in can upload directly to the background. The file type also goes unchecked, users could upload any type of file. These vulnerabilities has been fixed in version 1.18.5.

Vendors
dataease
Products
dataease
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.