man-group D-Tale
cpe:2.3:a:man:d-tale:*:*:*:*:*:*:*
- < 3.20.0
A remote code execution vulnerability exists in D-Tale versions prior to 3.20.0, specifically through the /save-column-filter endpoint. This issue allows attackers to execute arbitrary code on servers hosting D-Tale publicly.
Exploitation of this vulnerability allows for remote code execution on the server where D-Tale is hosted.
The vulnerability can be reproduced by sending a crafted request to the /save-column-filter endpoint with a column filter that includes malicious code, such as Python commands or references to local variables that can be exploited.
Users should upgrade to D-Tale version 3.20.0, where this vulnerability has been patched.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.