CVE-2022-46478
CRITICALdatax-web <2.1.2 - Command Injection
Title source: llmDescription
The RPC interface in datax-web v1.0.0 and v2.0.0 to v2.1.2 contains no permission checks by default which allows attackers to execute arbitrary commands via crafted Hessian serialized data.
Scores
CVSS v3
9.8
EPSS
0.0071
EPSS Percentile
72.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Classification
CWE
CWE-502
Status
published
Affected Products (1)
datax-web_project/datax-web
< 2.1.2
Timeline
Published
Jan 13, 2023
Tracked Since
Feb 18, 2026