Cross-Site Scripting Vulnerability in Dell EMC Isilon Web Administration Interface
CVE-2018-1189

4.8MEDIUM

Key Information:

Vendor
Dell
Vendor
CVE Published:
26 March 2018

Summary

The Dell EMC Isilon OneFS web administration interface is subject to a cross-site scripting vulnerability located within the Antivirus Page. This issue allows malicious administrators to potentially inject arbitrary HTML or JavaScript code within a user's browser session while they are interacting with the OneFS interface. Successful exploitation of this vulnerability could lead to the manipulation of the user's view or behavior on the affected website, posing a significant risk to the integrity of the system.

Affected Version(s)

Isilon OneFS versions between 8.1.0.0 - 8.1.0.1, 8.0.1.0 - 8.0.1.2, 8.0.0.0 - 8.0.0.6, versions 7.2.1.x and version 7.1.1.11

References

CVSS V3.1

Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.