Stored Cross-Site Scripting Vulnerability in Dell EMC XtremIO
CVE-2019-18578

9CRITICAL

Key Information:

Vendor
Dell
Status
Vendor
CVE Published:
13 March 2020

Summary

A vulnerability in Dell EMC XtremIO XMS allows a low-privileged remote user to execute stored cross-site scripting attacks. By exploiting this flaw, attackers can store malicious HTML or JavaScript code in application fields. When users subsequently access the compromised page, the malicious scripts can execute in the context of the XtremIO web application, potentially leading to unauthorized actions or data exposure.

Affected Version(s)

XtremIO < 6.3.0

References

CVSS V3.1

Score:
9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.