Cross-Site Scripting in Dell EMC ECS Software
CVE-2020-5317
6.2MEDIUM
What is CVE-2020-5317?
Dell EMC ECS versions earlier than 3.4.0.1 are susceptible to a Cross-Site Scripting (XSS) vulnerability. This security flaw allows a remote, authenticated attacker to inject malicious HTML or JavaScript code into a trusted application data store. When victims access this data store through their web browsers, the malicious script can execute in the context of the vulnerable web application, leading to potential data compromise and user impersonation. For further details, please refer to the official documentation.
Affected Version(s)
Elastic Cloud Storage < 3.4.0.1