Description
A vulnerability has been found in DataEase up to 2.10.25/2.10.26. Affected by this issue is the function buildTooltip of the file core/core-frontend/src/views/chart/components/js/panel/charts/map/symbolic-map.ts of the component Symbolic Map. Such manipulation of the argument canvasViewInfo[*].customAttr.tooltip.backgroundColor leads to cross site scripting. The attack may be performed from remote. The project was informed of the problem early through an issue report but has not responded yet.
Published: 2026-09-13
Score: 5.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Cross Site Scripting
Action: Mitigate
AI Analysis

Impact

The flaw exists in the Symbolic Map component of DataEase, where the canvasViewInfo[*].customAttr.tooltip.backgroundColor value is accepted without proper validation or escaping. This allows an attacker to embed malicious script code that will execute in the victim’s browser context, leading to remote code execution on the client side. The vulnerability occupies the categories CWE-79 and CWE-94, indicating improper input validation and unsafe template handling.

Affected Systems

DataEase software versions up to 2.10.25 and 2.10.26 are affected. The issue resides in the core-frontend source file core/core-frontend/src/views/chart/components/js/panel/charts/map/symbolic-map.ts within the Symbolic Map component.

Risk and Exploitability

The CVSS score of 5.1 reflects medium severity, and the EPSS score of < 1% indicates a very low, but non‑zero, probability of exploitation. DataEase is not listed in CISA’s KEV database. According to the description the attack may be performed remotely, typically by crafting a malicious tooltip value that is rendered by a victim’s browser when viewing a map. Successful exploitation would allow the attacker to run arbitrary scripts in the context of the user, potentially compromising credentials or performing unauthorized actions.

Generated by OpenCVE AI on September 15, 2026 at 16:38 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Contact DataEase support or check their official channels for the status of a fix and apply any released patch promptly.
  • If an upgrade is not currently possible, sanitize the customAttr.tooltip.backgroundColor input by removing or escaping any script tags or unsafe characters before it is rendered by the tooltip component.
  • Configure a strict Content‑Security‑Policy that disallows inline scripts, reducing the impact if the vulnerability is exploited.

Generated by OpenCVE AI on September 15, 2026 at 16:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 13 Sep 2026 15:00:00 +0000

Type Values Removed Values Added
Description A vulnerability has been found in DataEase up to 2.10.25/2.10.26. Affected by this issue is the function buildTooltip of the file core/core-frontend/src/views/chart/components/js/panel/charts/map/symbolic-map.ts of the component Symbolic Map. Such manipulation of the argument canvasViewInfo[*].customAttr.tooltip.backgroundColor leads to cross site scripting. The attack may be performed from remote. The project was informed of the problem early through an issue report but has not responded yet.
Title DataEase Symbolic Map symbolic-map.ts buildTooltip cross site scripting
First Time appeared Dataease
Dataease dataease
Weaknesses CWE-79
CWE-94
CPEs cpe:2.3:a:dataease:dataease:*:*:*:*:*:*:*:*
Vendors & Products Dataease
Dataease dataease
References
Metrics cvssV2_0

{'score': 4, 'vector': 'AV:N/AC:L/Au:S/C:N/I:P/A:N/E:ND/RL:ND/RC:UR'}

cvssV3_0

{'score': 3.5, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N/E:X/RL:X/RC:R'}

cvssV3_1

{'score': 3.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N/E:X/RL:X/RC:R'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X'}


Subscriptions

Dataease Dataease
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-15T13:59:49.298Z

Reserved: 2026-09-12T11:06:03.530Z

Link: CVE-2026-90529

cve-icon Vulnrichment

Updated: 2026-09-15T13:35:24.519Z

cve-icon NVD

Status : Deferred

Published: 2026-09-13T15:16:28.820

Modified: 2026-09-15T15:17:28.377

Link: CVE-2026-90529

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T16:45:06Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

  • CWE-94

    Improper Control of Generation of Code ('Code Injection')