Cross-Site Scripting Vulnerability in HPE iLO Amplifier Pack
CVE-2021-26580

6.1MEDIUM

Key Information:

Vendor
HP
Vendor
CVE Published:
1 April 2021

Summary

A potential security vulnerability has been detected in the HPE iLO Amplifier Pack that allows attackers to execute Cross-Site Scripting (XSS) attacks. This vulnerability could be exploited remotely, posing significant risks to web application security. To safeguard against this vulnerability, it is critical for users of HPE iLO Amplifier Pack to apply the latest software update, specifically version 1.95 or later, as provided by HPE. For detailed instructions, please refer to HPE's official documentation.

Affected Version(s)

iLO Amplifier Pack Prior to version 1.80

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.