cvedb.io
CVE-2025-48999
HIGH · CVSS 8.8
EPSS exploitation probability: 0%
Published 2025-06-03T21:15:22.107 · Last modified 2026-06-17T09:30:38.740

Summary

DataEase is an open source business intelligence and data visualization tool. A bypass of CVE-2025-46566's patch exists in versions prior to 2.10.10. In a malicious payload, `getUrlType()` retrieves `hostName`. Since the judgment statement returns false, it will not enter the if statement and will not be filtered. The payload can be directly concatenated at the replace location to construct a malicious JDBC statement. Version 2.10.10 contains a patch for the issue.

Affected products

dataease — dataease

Does this affect you?

Add your gear to cvedb and we'll alert you only when dataease ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.