The DataEase panel and dataset have a stored XSS vulnerability
CVE-2023-37257

5.4MEDIUM

Key Information:

Vendor

Dataease

Status
Vendor
CVE Published:
25 July 2023

What is CVE-2023-37257?

DataEase is an open source data visualization analysis tool. Prior to version 1.18.9, the DataEase panel and dataset have a stored cross-site scripting vulnerability. The vulnerability has been fixed in v1.18.9. There are no known workarounds.

Affected Version(s)

dataease < 1.18.9

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.