CVE-2025-69285 | Dataease SQLBot up to 1.4.x Endpoint uploadExcel to_sql missing authentication (GHSA-crfm-cch4-hjpv / EUVD-2025-206314)
A vulnerability marked as critical has been reported in Dataease SQLBot up to 1.4.x. The affected element is the function to_sql of the file /api/v1/datasource/uploadExcel of the component Endpoint. The manipulation leads to missing authentication.
This vulnerability is uniquely identified as CVE-2025-69285. The attack is possible to be carried out remotely. No exploit exists.
It is suggested to upgrade the affected component.