CVE-2023-25807

HIGH

DataEase < 1.18.3 - Stored Cross-Site Scripting via Dashboard Save

Title source: llm
STIX 2.1

Description

DataEase is an open source data visualization and analysis tool. When saving a dashboard on the DataEase platform saved data can be modified and store malicious code. This vulnerability can lead to the execution of malicious code stored by the attacker on the server side when the user accesses the dashboard. The vulnerability has been fixed in version 1.18.3.

Scores

CVSS v3 7.2
EPSS 0.0052
EPSS Percentile 40.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (1)
dataease/dataease < 1.18.3
Published Feb 28, 2023
Tracked Since Feb 18, 2026