DataGear pagingQueryData sql injection
CVE-2023-1571
9.8CRITICAL
What is CVE-2023-1571?
A SQL injection vulnerability exists in the DataGear application affecting versions up to 4.5.0. This flaw arises from improper handling of the 'queryOrder' parameter within the file /analysisProject/pagingQueryData. An attacker can exploit this vulnerability remotely to manipulate database queries, which could lead to unauthorized access to sensitive data. Users are urged to upgrade to version 4.5.1 to mitigate risks associated with this vulnerability.
Affected Version(s)
DataGear 4.0
DataGear 4.1
DataGear 4.2
