GHSA-xvhf-cv8g-xhprMediumCVSS 3.5
A vulnerability has been found in DataEase up to 2.10.25/2.10.26. Affected by this issue is the...
🔗 CVE IDs covered (1)
📋 Description
A vulnerability has been found in DataEase up to 2.10.25/2.10.26. Affected by this issue is the function buildTooltip of the file core/core-frontend/src/views/chart/components/js/panel/charts/map/symbolic-map.ts of the component Symbolic Map. Such manipulation of the argument canvasViewInfo[*].customAttr.tooltip.backgroundColor leads to cross site scripting. The attack may be performed from remote. The project was informed of the problem early through an issue report but has not responded yet.
🔗 References (8)
- https://nvd.nist.gov/vuln/detail/CVE-2026-90529
- https://github.com/dataease/dataease/issues/18846
- https://github.com/dataease/dataease
- https://vuldb.com/cve/CVE-2026-90529
- https://vuldb.com/submit/912538
- https://vuldb.com/vuln/403119
- https://vuldb.com/vuln/403119/cti
- https://github.com/advisories/GHSA-xvhf-cv8g-xhpr