SQL injection in DataEase - #VU151952

 

SQL injection in DataEase - #VU151952

Published: September 24, 2026


Vulnerability identifier: #VU151952
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-89
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute arbitrary code.

The vulnerability exists due to improper neutralization of special elements used in an SQL command in CREATE TABLE DDL generation when importing datasets with attacker-controlled column names. A remote user can upload a crafted Excel or CSV datasource with malicious column names to execute arbitrary code.

The embedded H2 engine must be enabled.


Affected software

DataEase

Remediation

Install security update from vendor's website.

DataEase - update to 2.10.27

External References

Related Security Bulletins