Authorization bypass through user-controlled key in DataEase - #VU151954
Published: September 24, 2026
Vulnerability details
The vulnerability allows a remote user to modify ticket-to-share associations or cause a denial of service.
The vulnerability exists due to improper authorization in the ShareTicketManage.saveTicket ticket-management function when processing ticket update requests. A remote user can submit crafted ticket update data to modify ticket-to-share associations or cause a denial of service.
Exploitation requires obtaining another user's ticket.