CVE-2025-49002

DataEase is an open source business intelligence and data visualization tool. Versions prior to version 2.10.10 have a flaw in the patch for CVE-2025-32966 that allow the patch to be bypassed through case insensitivity because INIT and RUNSCRIPT are prohibited. The vulnerability has been fixed in v2.10.10. No known workarounds are available.
Configurations

Configuration 1 (hide)

cpe:2.3:a:dataease:dataease:*:*:*:*:*:*:*:*

History

05 Jun 2025, 14:07

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
First Time Dataease
Dataease dataease
CPE cpe:2.3:a:dataease:dataease:*:*:*:*:*:*:*:*
CWE NVD-CWE-Other
References () https://github.com/dataease/dataease/security/advisories/GHSA-h7hj-4j78-cvc7 - () https://github.com/dataease/dataease/security/advisories/GHSA-h7hj-4j78-cvc7 - Exploit, Third Party Advisory
References () https://github.com/dataease/dataease/security/advisories/GHSA-999m-jv2p-5h34 - () https://github.com/dataease/dataease/security/advisories/GHSA-999m-jv2p-5h34 - Exploit, Third Party Advisory

04 Jun 2025, 14:15

Type Values Removed Values Added
CWE CWE-290

03 Jun 2025, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-06-03 21:15

Updated : 2025-06-05 14:07


NVD link : CVE-2025-49002

Mitre link : CVE-2025-49002


JSON object : View

Products Affected

dataease

  • dataease