Vulnerability Description
DataEase is an open source data visualization and analytics platform. In versions 2.10.13 and earlier, the /de2api/datasetData/tableField interface is vulnerable to SQL injection. An attacker can construct a malicious tableName parameter to execute arbitrary SQL commands. This issue is fixed in version 2.10.14. No known workarounds exist.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Dataease | Dataease | < 2.10.14 |
Related Weaknesses (CWE)
References
- https://github.com/dataease/dataease/commit/3c52cc26c4cca1000294346cf99a84b25d38Patch
- https://github.com/dataease/dataease/security/advisories/GHSA-54m5-xrw4-mv36ExploitVendor Advisory
FAQ
What is CVE-2025-62422?
CVE-2025-62422 is a vulnerability with a CVSS score of 8.8 (HIGH). DataEase is an open source data visualization and analytics platform. In versions 2.10.13 and earlier, the /de2api/datasetData/tableField interface is vulnerable to SQL injection. An attacker can cons...
How severe is CVE-2025-62422?
CVE-2025-62422 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-62422?
Check the references section above for vendor advisories and patch information. Affected products include: Dataease Dataease.