Reflected Cross-Site Scripting Vulnerability in Dell DM5500
CVE-2023-44301
5.4MEDIUM
Key Information:
- Vendor
Dell
- Vendor
- CVE Published:
- 4 December 2023
What is CVE-2023-44301?
The Dell DM5500 appliance versions 5.14.0.0 and prior are susceptible to a reflected cross-site scripting vulnerability. This issue allows an attacker with minimal privileges to inject and execute malicious scripts within a user's web browser, exploiting the vulnerable web application. Potential consequences of this vulnerability include unauthorized information access, session hijacking, and client-side request forgery, which can compromise the integrity and security of user interactions with the application.
Affected Version(s)
Dell PowerProtect Data Manager DM5500 Appliance DM5500 5.14 and below