Cross-Site Scripting in Dell EMC Isilon's OneFS Web Interface
CVE-2018-1187
4.8MEDIUM
Summary
Dell EMC Isilon’s OneFS web administration interface suffers from a cross-site scripting vulnerability that arises in the Network Configuration page. This flaw allows an attacker with administrative access to inject harmful HTML or JavaScript code into a user’s browser session. Consequently, this may lead to the compromise of the user's session data and sensitive information, making it critical for administrators to understand and address the potential implications for their systems.
Affected Version(s)
Isilon OneFS versions between 8.1.0.0 - 8.1.0.1, 8.0.1.0 - 8.0.1.2, 8.0.0.0 - 8.0.0.6
References
CVSS V3.1
Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved