Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2021-38239


SQL Injection vulnerability in dataease before 1.2.0, allows attackers to gain sensitive information via the orders parameter to /api/sys_msg/list/1/10.


Published

2023-02-15T22:15:11.310

Last Modified

2025-03-20T14:15:14.690

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.5 (HIGH)

Weaknesses
  • Type: Primary
    CWE-89
  • Type: Secondary
    CWE-89

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application dataease dataease < 1.2.0 Yes

References