Stored Cross-Site Scripting Vulnerability in Active IQ Unified Manager by NetApp
CVE-2022-23239
4.8MEDIUM
Summary
Active IQ Unified Manager versions prior to 9.11P1 present a vulnerability that allows administrative users to execute a Stored Cross-Site Scripting (XSS) attack. This vulnerability can lead to potential session hijacking and data theft, as attackers can inject malicious scripts into web pages viewed by users. Organizations should promptly update their systems to mitigate the risk associated with this security flaw. For further prevention measures and details, refer to the advisory provided by NetApp.
Affected Version(s)
Active IQ Unified Manager for VMware vSphere, Linux, and Microsoft Windows prior to 9.11P1
References
CVSS V3.1
Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved