PT-2026-90867 · Git · Dataease
CVSS v4.0
5.1
Medium
| Vector | AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X |
Name of the Vulnerable Software and Affected Versions
DataEase versions 2.10.25 through 2.10.26
Description
A remote cross site scripting issue exists in the Symbolic Map component. The problem occurs within the
buildTooltip() function located in the core/core-frontend/src/views/chart/components/js/panel/charts/map/symbolic-map.ts file. An attacker can exploit this by manipulating the canvasViewInfo[*].customAttr.tooltip.backgroundColor variable.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
XSS
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Dataease