VulnerabilityAnalyzed
CVE-2026-8724
The manipulation results in sql injection.
LOW 2.0EPSS 0.39%
Does this matter?
Lower severity and a low EPSS score (0.39%). Track it; it rarely justifies an emergency change on its own.
Description
A security flaw has been discovered in Dataease 2.10.20. Impacted is the function SqlparserUtils.transFilter of the file SqlparserUtils.java of the component Data Dashboard. The manipulation results in sql injection. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure.
- CVSS 4.0
- 2.0 LOWCVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
- EPSS
- 0.39% probability · 32th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-74, CWE-89
- Affected
- dataease/dataease
- Source
- cna@vuldb.com
References
- https://github.com/xpp3901/CVE_APPLY/tree/main/V-D001_DataEase_SqlVariable_InjectionExploit, Mitigation, Third Party Advisory
- https://vuldb.com/submit/804256Third Party Advisory, VDB Entry
- https://vuldb.com/vuln/364315Third Party Advisory, VDB Entry
- https://vuldb.com/vuln/364315/ctiPermissions Required, VDB Entry
- https://vuldb.com/submit/804256Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.