Impact
The flaw exists in the Symbolic Map component of DataEase, where the canvasViewInfo[*].customAttr.tooltip.backgroundColor value is accepted without proper validation or escaping. This allows an attacker to embed malicious script code that will execute in the victim’s browser context, leading to remote code execution on the client side. The vulnerability occupies the categories CWE-79 and CWE-94, indicating improper input validation and unsafe template handling.
Affected Systems
DataEase software versions up to 2.10.25 and 2.10.26 are affected. The issue resides in the core-frontend source file core/core-frontend/src/views/chart/components/js/panel/charts/map/symbolic-map.ts within the Symbolic Map component.
Risk and Exploitability
The CVSS score of 5.1 reflects medium severity, and the EPSS score of < 1% indicates a very low, but non‑zero, probability of exploitation. DataEase is not listed in CISA’s KEV database. According to the description the attack may be performed remotely, typically by crafting a malicious tooltip value that is rendered by a victim’s browser when viewing a map. Successful exploitation would allow the attacker to run arbitrary scripts in the context of the user, potentially compromising credentials or performing unauthorized actions.
OpenCVE Enrichment