CVE-2026-90529 | DataEase up to 2.10.25/2.10.26 Symbolic Map symbolic-map.ts buildTooltip cross site scripting (Issue 18846)

SecurityVulns

A vulnerability, which was classified as problematic, was found in DataEase up to 2.10.25/2.10.26. Affected by this issue is the function buildTooltip of the file core/core-frontend/src/views/chart/components/js/panel/charts/map/symbolic-map.ts of the component Symbolic Map. Such manipulation of the argument canvasViewInfo[*].customAttr.tooltip.backgroundColor leads to cross site scripting.

This vulnerability is listed as CVE-2026-90529. The attack may be performed from remote. There is no available exploit.

The project was informed of the problem early through an issue report but has not responded yet.VulDB Recent EntriesRead More