Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-90529

Опубликовано: 13 сент. 2026
Источник: nvd
CVSS3: 3.5
CVSS2: 4
EPSS Низкий

Описание

A vulnerability has been found in DataEase up to 2.10.25/2.10.26. Affected by this issue is the function buildTooltip of the file core/core-frontend/src/views/chart/components/js/panel/charts/map/symbolic-map.ts of the component Symbolic Map. Such manipulation of the argument canvasViewInfo[*].customAttr.tooltip.backgroundColor leads to cross site scripting. The attack may be performed from remote. The project was informed of the problem early through an issue report but has not responded yet.

EPSS

Процентиль: 10%
0.00199
Низкий

3.5 Low

CVSS3

4 Medium

CVSS2

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 3.5
github
8 дней назад

A vulnerability has been found in DataEase up to 2.10.25/2.10.26. Affected by this issue is the function buildTooltip of the file core/core-frontend/src/views/chart/components/js/panel/charts/map/symbolic-map.ts of the component Symbolic Map. Such manipulation of the argument canvasViewInfo[*].customAttr.tooltip.backgroundColor leads to cross site scripting. The attack may be performed from remote. The project was informed of the problem early through an issue report but has not responded yet.

EPSS

Процентиль: 10%
0.00199
Низкий

3.5 Low

CVSS3

4 Medium

CVSS2

Дефекты

CWE-79