PT-2025-42628 · Dataease · Dataease

Published

2025-10-17

·

Updated

2025-10-24

·

CVE-2025-62421

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N
Name of the Vulnerable Software and Affected Versions DataEase versions through 2.10.13
Description DataEase is a data visualization and analytics platform. A stored cross-site scripting issue exists because of inadequate file upload validation and authentication bypass. The upload/{fileId} route within the StaticResourceApi interface allows users to control the filename and extension of uploaded files. The WhitelistUtils#match method incorrectly deems URLs ending with extensions like .js as safe, bypassing permission checks. This enables attackers to upload HTML files containing malicious JavaScript by specifying arbitrary file extensions, such as accessing "upload/1.js". The TokenFilter is involved in the permission validation process.
Recommendations Update to version 2.10.14 or later.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-62421
GHSA-2WMV-RR3P-PF43

Affected Products

Dataease