Sploitus

CVE-2023-40183

No indexed exploits for CVE-2023-40183 yet

DataEase is an open source data visualization and analysis tool. Prior to version 1.18.11, DataEase has a vulnerability that allows an attacker to to obtain user cookies. The program only uses the `ImageIO.read()` method to determine whether the file is an image file or not. There is no whitelisting restriction on file suffixes. This allows the attacker to synthesize the attack code into an image for uploading and change the file extension to html. The attacker may steal user cookies by accessing links. The vulnerability has been fixed in v1.18.11. There are no known workarounds.

Affected products
Dataease
Dataease
< 1.18.11
Fix
Available
CVSS 3.1
7.5 HIGH
EPSS
0.6% (47th percentile)
Weakness
CWE-434
NVD status
Modified
Published
2023-09-21
CVE-2023-40183 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2023-40183 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2023-40183 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.