DataEase dashboard has a stored XSS vulnerability
CVE-2023-25807
7.2HIGH
What is CVE-2023-25807?
DataEase, an open-source data visualization and analysis tool, contains a vulnerability allowing attackers to modify saved data when users save a dashboard. This flaw can enable the execution of malicious code on the server, potentially compromising the integrity of the application and its users. Users are encouraged to update to version 1.18.3 or later to mitigate this risk.
Affected Version(s)
dataease < 1.18.3