peter bassill · operator
$ cve CVE-2025-49002 JSON

CVE-2025-49002

9.8
CRITICAL · CVSS 3.1 · EPSS 50% (pctl 99)

Patch early

EPSS 50% — above the 10% action threshold.

Description

DataEase is an open source business intelligence and data visualization tool. Versions prior to version 2.10.10 have a flaw in the patch for CVE-2025-32966 that allow the patch to be bypassed through case insensitivity because INIT and RUNSCRIPT are prohibited. The vulnerability has been fixed in v2.10.10. No known workarounds are available.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS49.99% — more likely to be exploited than 99% of all CVEs
WeaknessCWE-290
On CISA KEVno
Public exploitnone known
Published2025-06-03
Last modified2026-06-17

Affected (1)

VendorProduct
dataeasedataease

References

→ the Explorer  ·  watch your stack  ·  NVD