Impact
DataEase versions prior to 2.10.24 render dashboard text components using Vue's v-html attribute without server‑side sanitization. An authenticated user who can edit dashboard content can inject arbitrary HTML and JavaScript that is stored and later executed whenever another user or any shared‑link visitor opens the dashboard. The injected script runs in the victim’s browser, allowing a malicious actor to steal session cookies, hijack the user session, or perform other client‑side attacks. The vulnerability is identified as CWE‑79 and constitutes a stored XSS flaw.
Affected Systems
All DataEase releases older than 2.10.24 are affected. The product is named DataEase by the vendor DataEase. No additional vendors or product variants are listed as impacted.
Risk and Exploitability
The CVSS score of 5.1 indicates moderate severity. The EPSS score of < 1% suggests a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires the attacker to be authenticated and to have permission to edit dashboard content; once the payload is stored the risk propagates to any user who views the dashboard, including those accessing shared links, thereby exposing a wide potential audience but limiting the initial attack surface to users with editing rights.
OpenCVE Enrichment