Impact
DataEase, an open source data visualization and analysis tool, suffered a flaw that permitted an authenticated attacker to bypass the H2 zip protocol and file dropper checks by uploading a zip archive disguised as a. The zip handler then processed the archive without validating its true type, enabling malicious payloads to be extracted and executed on the server. This results in remote code execution under the privileges of the uploading account, classified as CWE-434 insecure file upload.
Affected Systems
All DataEase installations running a version earlier than 2.10.24, including 2.10.23 and earlier, are vulnerable.
Risk and Exploitability
The CV, while the EPSS score of <1% indicates a low current likelihood of exploitation and the issue is not listed in CISA KEV. Exploitation requires an authenticated session and interaction with the FontManage.saveFile endpoint; the attacker can bypass file‑dropper protections by renaming a malicious zip to a font file. Successful exploitation allows arbitrary code to run with the application’s service user privileges, creating significant risk for users with elevated or compromised credentials.
OpenCVE Enrichment