Stored Cross-Site Scripting in DataEase Data Visualization Platform
CVE-2025-62421

5.5MEDIUM

Key Information:

Vendor

Dataease

Status
Vendor
CVE Published:
17 October 2025

What is CVE-2025-62421?

The DataEase platform has a stored cross-site scripting vulnerability that affects versions up to 2.10.13. It arises from inadequate validation of file uploads, allowing an attacker to manipulate URL path parameters during file uploads. The system's permission validation process incorrectly identifies uploaded files with certain extensions (e.g., .js) as safe, leading to a bypass of critical security checks. This flaw allows for the potential upload of malicious HTML files that can execute harmful JavaScript code within the application's context. The vulnerability has been addressed in version 2.10.14, but no workarounds are available.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

dataease < 2.10.14

References

CVSS V4

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.