Impact
The vulnerability is a classic Cross‑Site Scripting flaw (CWE‑80). In KendoReact chart tooltips the component displays the point value as raw HTML without encoding, both in single‑point and shared tooltips. An attacker with limited privileges who can influence a bound string value can embed arbitrary HTML containing event handlers, which are then executed in a user's browser when they hover over the data point. Successful exploitation can lead to the theft or tampering of application data.
Affected Systems
The affected product is Progress Software's KendoReact (React charting library). Versions starting with 1.1.0 up to, but not including, 16.2.0 are vulnerable. Applications that use the default tooltip configuration of the chart component and receive untrusted data are exposed. The issue applies to any web application that integrates this library.
Risk and Exploitability
The CVSS score of 5.4 indicates moderate risk. No EPSS score is available, so the likelihood of exploitation cannot be quantified from the data. The vulnerability is not currently catalogued in CISA’s KEV. The likely attack vector is client‑side; an attacker must manage to supply a crafted string that is bound to chart data, which can be done via user input, API responses, or injection into a data source. Once the victim hovers over the data point, the embedded script runs, compromising data confidentiality and integrity.
OpenCVE Enrichment