Dataease v1.11.1 was discovered to contain a SQL injection vulnerability via the parameter dataSourceId. Version 1.11.2 contains a fix.
References
https://nvd.nist.gov/vuln/detail/CVE-2022-34115
https://github.com/dataease/dataease/issues/2428
https:/…