Stored Cross-Site Scripting in DataEase Data Visualization Platform
CVE-2025-62421
What is CVE-2025-62421?
The DataEase platform has a stored cross-site scripting vulnerability that affects versions up to 2.10.13. It arises from inadequate validation of file uploads, allowing an attacker to manipulate URL path parameters during file uploads. The system's permission validation process incorrectly identifies uploaded files with certain extensions (e.g., .js) as safe, leading to a bypass of critical security checks. This flaw allows for the potential upload of malicious HTML files that can execute harmful JavaScript code within the application's context. The vulnerability has been addressed in version 2.10.14, but no workarounds are available.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
dataease < 2.10.14
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
