CVE-2023-25807: DataEase dashboard has a stored XSS vulnerability
DataEase is an open source data visualization and analysis tool. When saving a dashboard on the DataEase platform saved data can be modified and store malicious code. This vulnerability can lead to the execution of malicious code stored by the attacker on the server side when the user accesses the dashboard. The vulnerability has been fixed in version 1.18.3.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2023-25807?
CVE-2023-25807 is a vulnerability in the DataEase open source data visualization and analysis tool that allows an attacker to execute malicious code on the server side.
How does CVE-2023-25807 affect DataEase?
CVE-2023-25807 affects DataEase by allowing an attacker to modify and store malicious code in the saved data on the platform, which can then be executed when a user accesses the dashboard.
What is the severity of CVE-2023-25807?
CVE-2023-25807 has a severity rating of high with a severity value of 5.4.
Which version of DataEase is affected by CVE-2023-25807?
DataEase version 1.18.3 is affected by CVE-2023-25807.
How can CVE-2023-25807 be fixed?
To fix CVE-2023-25807, users should update to a version of DataEase that includes the patch provided by the vendor.