Cross-Site Scripting Vulnerability in OVA file upload feature
CVE-2019-3708

8.3HIGH

Key Information:

Vendor
Dell
Vendor
CVE Published:
17 April 2019

Summary

IsilonSD Management Server 1.1.0 contains a cross-site scripting vulnerability while uploading an OVA file. A remote attacker can trick an admin user to potentially exploit this vulnerability to execute malicious HTML or JavaScript code in the context of the admin user.

Affected Version(s)

Dell EMC IsilonSD Management Server 1.1.0

References

CVSS V3.1

Score:
8.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Dell EMC would like to thank Jarrod Farncomb for reporting this vulnerability.
.