Reflected Cross-Site Scripting Vulnerability in Dell EMC iDRAC9 Web Application
CVE-2020-26198
6.1MEDIUM
Key Information:
- Vendor
Dell
- Vendor
- CVE Published:
- 16 December 2020
What is CVE-2020-26198?
The Dell EMC iDRAC9 web application prior to versions 4.32.10.00 and 4.40.00.00 is susceptible to a reflected cross-site scripting vulnerability. This issue allows remote attackers to execute malicious HTML or JavaScript in the context of a victim's browser. By deceiving users into clicking on a specially crafted link, an attacker could potentially compromise user sessions or redirect victims to malicious sites. It’s crucial for organizations using affected versions to update to prevent exploitation.
Affected Version(s)
Integrated Dell Remote Access Controller (iDRAC) < 4.32.10.00 and 4.40.00.00