---
id: CVE-2023-7299
title: A vulnerability was found in DataGear up to 4.60
summary: >-
  A vulnerability was found in DataGear up to 4.60. It has been declared as
  critical. This vulnerability affects unknown code of the file
  /dataSet/resolveSql. The manipulation of the argument sql leads to sql
  injection. The attack can be i…
severity: medium
cvss: 6.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L'
cwe:
  - CWE-74
  - CWE-89
  - CWE-89
vendor: datagear
product: datagear
affected:
  - datagear < 4.7.0
patched:
  - datagear 4.7.0
published: '2024-11-23'
updated: '2026-09-03'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2023-7299'
references:
  - url: 'https://github.com/datageartech/datagear/issues/29'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?ctiid.285658'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?id.285658'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?submit.442943'
    label: cna@vuldb.com
tags:
  - nvd
epss: 0.00635
epssPercentile: 0.49049
ingestedAt: '2026-09-03T02:54:37.754Z'
---

## Overview

A vulnerability was found in DataGear up to 4.60. It has been declared as critical. This vulnerability affects unknown code of the file /dataSet/resolveSql. The manipulation of the argument sql leads to sql injection. The attack can be initiated remotely. Upgrading to version 4.7.0 is able to address this issue. It is recommended to upgrade the affected component.

## Affected

- `datagear < 4.7.0`

## Remediation

Upgrade past the affected range:

- `datagear 4.7.0`
