Cross-site scripting in DataEase - #VU140509
Published: July 30, 2026
DataEase
Detailed vulnerability description
The vulnerability allows a remote user to execute arbitrary JavaScript in a victim's browser session.
The vulnerability exists due to improper neutralization of input during web page generation in the datasource and dataset folder move dialog search highlighting logic when rendering stored folder names as HTML. A remote user can create a folder with a crafted name to execute arbitrary JavaScript in a victim's browser session.
User interaction is required: the victim must open the "Move to" dialog and type in the search box.