PT-2023-25860 · Dataease · Dataease
5Uper8Ean
·
Published
2023-07-25
·
Updated
2023-08-01
·
CVE-2023-37257
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
DataEase versions prior to 1.18.9
Description
DataEase is an open source data visualization analysis tool. The DataEase panel and dataset have a stored cross-site scripting vulnerability. The issue has been fixed in version 1.18.9. There are no known workarounds for this issue.
Recommendations
For versions prior to 1.18.9, update to version 1.18.9 to resolve the issue. As a temporary workaround, consider restricting access to the DataEase panel and dataset until the update can be applied.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Dataease