Impact
The vulnerability is a directory traversal flaw in DataEase prior to version 1.18.10. A remote attacker can craft a request to StaticResourceController.java to read arbitrary files on the host filesystem, potentially revealing configuration files or other sensitive data. The flaw is classified as CWE‑23.
Affected Systems
The vulnerability affects all installations of DataEase running any version prior to 1.18.10. Users of earlier releases are susceptible to reading arbitrary files from the host operating system through the StaticResourceController endpoint.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity. The exploit can be performed via a standard HTTP request. It is inferred that authentication is not required; the description does not mention a need for elevated privileges, so remediation focuses on preventing unauthenticated remote access. The EPSS score of 1% suggests low real‑world exploitation likelihood. The vulnerability is not listed in the CISA KEV catalog, but the straightforward attack path still poses a non‑negligible risk to exposed servers.
OpenCVE Enrichment