DataEase prior to version 2.10.8 contains a remote code execution caused by insecure backend JDBC link handling, letting authenticated users execute arbitrary code, exploit requires user authentication.
id: CVE-2025-32966
info:
name: DataEase 2.10.4-2.10.7 - Remote Code Execution
author: ChrisJr40
...