#VU126342 SQL injection in DataEase - CVE-2025-62422

 

#VU126342 SQL injection in DataEase - CVE-2025-62422

Published: April 16, 2026


Vulnerability identifier: #VU126342
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2025-62422
CWE-ID: CWE-89
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
DataEase
Software vendor:
DataEase

Description

The vulnerability allows a remote user to execute arbitrary SQL commands.

The vulnerability exists due to SQL injection in the /de2api/datasetData/tableField interface when handling a crafted tableName parameter. A remote user can send a specially crafted request to execute arbitrary SQL commands.

Exploitation requires access to the vulnerable interface and the ability to supply the tableName parameter.


Remediation

Install security update from vendor's website.

External links