Cross-site scripting in DataEase - #VU140509

 

Cross-site scripting in DataEase - #VU140509

Published: July 30, 2026


Vulnerability identifier: #VU140509
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:U/U:Clear
CVE-ID: N/A
CWE-ID: CWE-79
Exploitation vector: Remote access
Exploit availability: No public exploit available
Affected software:
DataEase

Detailed vulnerability description

The vulnerability allows a remote user to execute arbitrary JavaScript in a victim's browser session.

The vulnerability exists due to improper neutralization of input during web page generation in the datasource and dataset folder move dialog search highlighting logic when rendering stored folder names as HTML. A remote user can create a folder with a crafted name to execute arbitrary JavaScript in a victim's browser session.

User interaction is required: the victim must open the "Move to" dialog and type in the search box.


Remediation

Install security update from vendor's website.

Sources