Stored Cross-Site Scripting Vulnerability in Dell EMC XtremIO
CVE-2019-18578
9CRITICAL
Summary
A vulnerability in Dell EMC XtremIO XMS allows a low-privileged remote user to execute stored cross-site scripting attacks. By exploiting this flaw, attackers can store malicious HTML or JavaScript code in application fields. When users subsequently access the compromised page, the malicious scripts can execute in the context of the XtremIO web application, potentially leading to unauthorized actions or data exposure.
Affected Version(s)
XtremIO < 6.3.0
References
CVSS V3.1
Score:
9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved