Impact
The vulnerability originates from the default Kendo UI Chart tooltip, which renders the formatted point value as raw HTML without encoding. An attacker who can influence a string value bound to a chart can supply malicious HTML containing event handlers. When a user hovers over the affected data point, the injected JavaScript runs in the user's browser, exposing or modifying data the application handles. This can lead to confidentiality and integrity compromise of information accessed by the affected application.
Affected Systems
The flaw exists in Progress Software’s Kendo UI for Vue (kendo-vue-charts) component library, affecting all releases from version 2.5.0 up through the last out‑of‑date release before 16.2.0. No other vendors or products are currently listed as impacted.
Risk and Exploitability
The CVSS score of 5.4 indicates moderate severity, and no EPSS data is available, but the issue is exploitable by any attacker who can provide chart data, including low‑privilege users. The vulnerability does not require authentication and can be triggered whenever a user hovers over a chart point, thus posing a potential risk of data theft or session hijack. The flaw is not yet listed in the CISA KEV catalog; however, due to its client‑side nature and the widespread use of the library, it remains a relevant threat.
OpenCVE Enrichment