SQL injection in DataEase - #VU151953
Published: September 24, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information or cause a denial of service.
The vulnerability exists due to improper neutralization of special elements in an SQL command in Field2SQLObj.field2sqlObj() when processing a dateFormat parameter in single-datasource queries. A remote user can submit a crafted dateFormat parameter to disclose sensitive information or cause a denial of service.
Exploitation requires dataset or chart editing permissions and a custom date format configuration.