CyberRota Analysis
AI-GeneratedThe vulnerability affects the Symbolic Map component in DataEase versions up to 2.10.26, specifically within the buildTooltip function, where improper handling of the tooltip background color can lead to cross-site scripting (XSS) attacks. This issue allows remote attackers to inject malicious scripts, potentially compromising user data and application integrity. Organizations using affected versions should prioritize remediation to mitigate the risk of XSS exploitation.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
A vulnerability has been found in DataEase up to 2.10.25/2.10.26. Affected by this issue is the function buildTooltip of the file core/core-frontend/src/views/chart/components/js/panel/charts/map/symbolic-map.ts of the component Symbolic Map. Such manipulation of the argument canvasViewInfo[*].customAttr.tooltip.backgroundColor leads to cross site scripting. The attack may be performed from remote. The project was informed of the problem early through an issue report but has not responded yet.