An issue in the component /api/plugin/upload of Dataease v1.11.1 allows attackers to execute arbitrary code via a crafted plugin.
| Software | From | Fixed in |
|---|---|---|
| dataease / dataease | 1.11.1 | 1.11.1.x |
io.dataease / dataease-plugin-common
|
- | 1.11.2 |