#VU126343 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in DataEase - CVE-2025-62421
Published: April 16, 2026
DataEase
DataEase
Description
The vulnerability allows a remote user to execute arbitrary script in a user's browser.
The vulnerability exists due to improper access control in the StaticResourceApi upload route when handling crafted file upload requests that use a whitelisted script-like path. A remote user can upload a crafted HTML file and access it through a path ending in a permitted extension to execute arbitrary script in a user's browser.