CVE-2026-32137
EUVD-2026-1164712.03.2026, 18:16
Dataease is an open source data visualization analysis tool. Prior to 2.10.20, The table parameter for /de2api/datasource/previewData is directly concatenated into the SQL statement without any filtering or parameterization. Since tableName is a user-controllable string, attackers can inject malicious SQL statements by constructing malicious table names. This vulnerability is fixed in 2.10.20.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| dataease | dataease | 𝑥 < 2.10.20 |
𝑥
= Vulnerable software versions