Impact
DataGear up to version 5.0.0 contains a flaw in the HtmlTplDashboardWidgetHtmlRenderer function of the Chart Name Handler. Manipulating the Title argument allows an attacker to inject arbitrary JavaScript into the dashboard view, leading to client‑side script execution. This weakness is classified as CWE‑79 and CWE‑94 and can be exploited remotely. The impact includes data theft, session hijacking, and page defacement.
Affected Systems
The affected system is DataGear, specifically internal chart name handling code in the HtmlTplDashboardWidgetHtmlRenderer component. All releases up to and including 5.0.0 are vulnerable; newer releases beyond 5.0.0 are presumed to be unaffected.
Risk and Exploitability
The CVSS score of 4.8 indicates moderate severity, and no EPSS score is available, so the likelihood of widespread exploitation is unknown. The vulnerability is not listed in the CISA KEV catalog, but the public disclosure and prototype exploit imply that attackers can trigger this XSS remotely via any web interface that accepts chart titles. The attack vector is inferred to be web‑based input manipulation.
OpenCVE Enrichment