Описание
DataEase is an open source data visualization analysis tool. Prior to version 1.18.9, the DataEase panel and dataset have a stored cross-site scripting vulnerability. The vulnerability has been fixed in v1.18.9. There are no known workarounds.
Ссылки
- Release Notes
- ExploitVendor Advisory
- Release Notes
- ExploitVendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 1.18.9 (исключая)
cpe:2.3:a:dataease:dataease:*:*:*:*:*:*:*:*
EPSS
Процентиль: 63%
0.00452
Низкий
5.4 Medium
CVSS3
Дефекты
CWE-79
EPSS
Процентиль: 63%
0.00452
Низкий
5.4 Medium
CVSS3
Дефекты
CWE-79