An issue in the component /api/plugin/upload of Dataease v1.11.1 allows attackers to execute arbitrary code via a crafted plugin.
Affected Software
| Name | Vendor | Start Version | End Version |
|---|
| Dataease | Dataease | 1.11.1 (including) | 1.11.1 (including) |
References