Dataease is an open source data visualization and analysis tool. The permissions for the file upload interface is not checked so users who are not logged in can upload directly to the background. The file type also goes unchecked, users could upload any type of file. These vulnerabilities has been fixed in version 1.18.5.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: GitHub_M
Published: 2023-03-24T20:39:23.223Z
Updated: 2024-08-02T12:38:25.335Z
Reserved: 2023-03-15T15:59:10.053Z
Link: CVE-2023-28435
Vulnrichment
No data.
NVD
Status : Modified
Published: 2023-03-24T21:15:06.860
Modified: 2024-11-21T07:55:03.660
Link: CVE-2023-28435
Redhat
No data.