CVE-2023-28437
Dataease is an open source data visualization and analysis tool. The blacklist for SQL injection protection is missing entries. This vulnerability has been fixed in version 1.18.5. There are no known workarounds.
- Affected products
- Dataease
- Dataease
- < 1.18.5
- Fix
- Available
- CVSS 3.1
- 9.8 CRITICAL
- EPSS
- 0.9% (56th percentile)
- Weakness
- CWE-89
- NVD status
- Modified
- Published
- 2023-03-24
CVE-2023-28437 at NVD
No indexed exploits for CVE-2023-28437 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2023-28437 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.