Sceawere

Vulnerability Detail

CVE-2026-19110UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

DataGear Cross-Site Scripting Vulnerability

Vulnerability Metadata

Severity
Low
Score / CVSS
2.4
Creation Date
1d ago
Vendor
n/a
Product
DataGear
Attack Type
Cross Site Scripting
Vector String
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

A vulnerability was determined in DataGear up to 5.0.0. The impacted element is the function HtmlTplDashboardWidgetHtmlRenderer of the file HtmlTplDashboardWidgetHtmlRenderer.java of the component Chart Name Handler. This manipulation of the argument Title causes cross site scripting. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "2.4",
  "pubDate": "2026-08-06T22:16:55.237Z",
  "pubdate": "2026-08-06T22:16:55.237Z",
  "executiveSummary": "A cross-site scripting (XSS) vulnerability has been identified in DataGear up to version 5.0.0. The security flaw specifically resides within the Chart Name Handler component, affecting the HtmlTplDashboardWidgetHtmlRenderer function inside the HtmlTplDashboardWidgetHtmlRenderer.java file.\nThe vulnerability allows remote attackers to manipulate the Title argument, leading to the execution of malicious scripts within the context of a victim's browser session. Successful exploitation of this vulnerability can result in unauthorized actions, session hijacking, credential theft, and the manipulation of the user interface.\nThe impacted system is DataGear up to version 5.0.0. The risk implications are significant due to the remote vector and the potential for direct client-side compromise. Attack capabilities include remote exploitation without prior privileges if network access is permitted. Public disclosure of an exploit increases the likelihood of active exploitation attempts.\nThe vendor was contacted early regarding this disclosure but failed to provide any response or official patch. Consequently, organizations utilizing the affected software must rely on defensive hardening measures and monitoring to mitigate potential exploitation risks until a vendor-supplied update becomes available.",
  "technicalDetails": "The vulnerability is a classic cross-site scripting (XSS) flaw stemming from insufficient input sanitization and improper output encoding within the Chart Name Handler component of DataGear up to version 5.0.0.\nThe vulnerable implementation resides in the HtmlTplDashboardWidgetHtmlRenderer function within the HtmlTplDashboardWidgetHtmlRenderer.java source file. Specifically, the function processes user-supplied input via the Title argument and dynamically renders it into the generated HTML output without applying adequate context-aware HTML or JavaScript escaping.\nExploitation of this vulnerability occurs remotely over the network. An unauthenticated or authenticated attacker, depending on the application deployment and endpoint exposure, can supply crafted input containing malicious JavaScript payloads into the Title parameter. When a targeted user views the dashboard or widget rendered by the affected component, the application incorporates the malicious payload directly into the Document Object Model (DOM).\nThe attack flow proceeds as follows: First, the attacker crafts a malicious HTTP request or URL containing the XSS payload targeting the Title argument within the dashboard widget functionality. Second, the vulnerable HtmlTplDashboardWidgetHtmlRenderer function processes this input and embeds it into the resulting HTML response without neutralization. Third, the victim's web browser parses the response, executing the injected script under the victim's session context.\nPost-exploitation impact includes the execution of arbitrary script code in the victim's browser, enabling session token theft, access to sensitive local storage data, redirection to malicious external sites, and unauthorized interactions with the DataGear API on behalf of the authenticated user. The lack of vendor response and absence of an official patch necessitate strict adherence to alternative defensive controls."
}
CVE-2026-19110: DataGear Cross-Site Scripting Vulnerability (LOW Severity, CVSS: 2.4) - Sceawere