Unrated severityNVD Advisory· Published Oct 17, 2025· Updated Oct 17, 2025
DataEase SQL injection vulnerability
CVE-2025-62422
Description
DataEase is an open source data visualization and analytics platform. In versions 2.10.13 and earlier, the /de2api/datasetData/tableField interface is vulnerable to SQL injection. An attacker can construct a malicious tableName parameter to execute arbitrary SQL commands. This issue is fixed in version 2.10.14. No known workarounds exist.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- github.com/dataease/dataease/commit/3c52cc26c4cca1000294346cf99a84b25d38bfb2mitrex_refsource_MISC
- github.com/dataease/dataease/security/advisories/GHSA-54m5-xrw4-mv36mitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.