DataEase is an open source data visualization and analysis tool. The API interface for DataEase delete dashboard and delete system messages is vulnerable to insecure direct object references (IDOR). This could result in a user deleting another user's dashboard or messages or interfering with the interface for marking messages read. The vulnerability has been fixed in v1.18.7. There are no known workarounds aside from upgrading.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2023-06-01T15:05:00.439Z

Updated: 2024-08-02T15:10:24.609Z

Reserved: 2023-05-08T13:26:03.878Z

Link: CVE-2023-32310

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2023-06-01T16:15:09.643

Modified: 2023-06-09T17:24:45.173

Link: CVE-2023-32310

cve-icon Redhat

No data.