Cross-Site Scripting in Dell EMC ECS Software
CVE-2020-5317

6.2MEDIUM

Key Information:

Vendor
Dell
Vendor
CVE Published:
6 February 2020

Summary

Dell EMC ECS versions earlier than 3.4.0.1 are susceptible to a Cross-Site Scripting (XSS) vulnerability. This security flaw allows a remote, authenticated attacker to inject malicious HTML or JavaScript code into a trusted application data store. When victims access this data store through their web browsers, the malicious script can execute in the context of the vulnerable web application, leading to potential data compromise and user impersonation. For further details, please refer to the official documentation.

Affected Version(s)

Elastic Cloud Storage < 3.4.0.1

References

CVSS V3.1

Score:
6.2
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.