Cross-Site Scripting in Dell EMC Isilon's OneFS Web Interface
CVE-2018-1187

4.8MEDIUM

Key Information:

Vendor
Dell
Vendor
CVE Published:
26 March 2018

Summary

Dell EMC Isilon’s OneFS web administration interface suffers from a cross-site scripting vulnerability that arises in the Network Configuration page. This flaw allows an attacker with administrative access to inject harmful HTML or JavaScript code into a user’s browser session. Consequently, this may lead to the compromise of the user's session data and sensitive information, making it critical for administrators to understand and address the potential implications for their systems.

Affected Version(s)

Isilon OneFS versions between 8.1.0.0 - 8.1.0.1, 8.0.1.0 - 8.0.1.2, 8.0.0.0 - 8.0.0.6

References

CVSS V3.1

Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.