The api interface for DataEase delete dashboard and delete system messages is vulnerable to IDOR.
The interface to delete the dashboard:

The interface to delete system messages:

Affected versions: <= 1.18.6
The vulnerability has been fixed in v1.18.7.
It is recommended to upgrade the version to v1.18.7.
If you have any questions or comments about this advisory:
Open an issue in https://github.com/dataease/dataease Email us at wei@fit2cloud.com
{
"cwe_ids": [
"CWE-639"
],
"github_reviewed": true,
"github_reviewed_at": "2023-06-02T17:09:17Z",
"nvd_published_at": "2023-06-01T16:15:09Z",
"severity": "HIGH"
}