CVE-2021-38239
15.02.2023, 22:15
SQL Injection vulnerability in dataease before 1.2.0, allows attackers to gain sensitive information via the orders parameter to /api/sys_msg/list/1/10.
Vendor | Product | Version |
---|---|---|
dataease | dataease | 𝑥 < 1.2.0 |
𝑥
= Vulnerable software versions