Reflected Cross-Site Scripting Vulnerability in Dell Wyse Management Suite
CVE-2022-33929
6.1MEDIUM
Summary
Dell Wyse Management Suite versions 3.6.1 and earlier are susceptible to a reflected cross-site scripting vulnerability located in the EndUserSummary page. This flaw allows an authenticated attacker to inject and execute malicious HTML or JavaScript code within the web browser of an impacted user. If exploited, this vulnerability may lead to serious consequences such as information disclosure, session hijacking, and client-side request forgery, posing a significant risk to user security and data integrity.
Affected Version(s)
Wyse Management Suite < 3.7
References
CVSS V3.1
Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved