#VU126342 SQL injection in DataEase - CVE-2025-62422
Published: April 16, 2026
DataEase
DataEase
Description
The vulnerability allows a remote user to execute arbitrary SQL commands.
The vulnerability exists due to SQL injection in the /de2api/datasetData/tableField interface when handling a crafted tableName parameter. A remote user can send a specially crafted request to execute arbitrary SQL commands.
Exploitation requires access to the vulnerable interface and the ability to supply the tableName parameter.