A security flaw has been discovered in Dataease 2.10.20. Impacted is the function SqlparserUtils.transFilter of the file SqlparserUtils.java of the component Data Dashboard. The manipulation results in sql injection. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure.
References
| Link | Resource |
|---|---|
| https://github.com/xpp3901/CVE_APPLY/tree/main/V-D001_DataEase_SqlVariable_Injection | Exploit Mitigation Third Party Advisory |
| https://vuldb.com/submit/804256 | Third Party Advisory VDB Entry |
| https://vuldb.com/vuln/364315 | Third Party Advisory VDB Entry |
| https://vuldb.com/vuln/364315/cti | Permissions Required VDB Entry |
| https://vuldb.com/submit/804256 | Third Party Advisory VDB Entry |
Configurations
History
19 May 2026, 19:04
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:dataease:dataease:2.10.20:*:*:*:*:*:*:* | |
| First Time |
Dataease
Dataease dataease |
|
| References | () https://github.com/xpp3901/CVE_APPLY/tree/main/V-D001_DataEase_SqlVariable_Injection - Exploit, Mitigation, Third Party Advisory | |
| References | () https://vuldb.com/submit/804256 - Third Party Advisory, VDB Entry | |
| References | () https://vuldb.com/vuln/364315 - Third Party Advisory, VDB Entry | |
| References | () https://vuldb.com/vuln/364315/cti - Permissions Required, VDB Entry |
18 May 2026, 20:16
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://vuldb.com/submit/804256 - |
17 May 2026, 02:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-05-17 02:16
Updated : 2026-05-19 19:04
NVD link : CVE-2026-8724
Mitre link : CVE-2026-8724
CVE.ORG link : CVE-2026-8724
JSON object : View
Products Affected
dataease
- dataease
