XSS Vulnerability in Dell Update Manager Plugin Affects Multiple Versions
CVE-2025-22402

5.4MEDIUM

Key Information:

Vendor
Dell
Vendor
CVE Published:
7 February 2025

Summary

The Dell Update Manager Plugin versions 1.5.0 through 1.6.0 contain a security flaw characterized by improper neutralization of script-related HTML tags in web pages. This vulnerability could be exploited by low privileged attackers with remote access, potentially leading to unauthorized information exposure. Organizations using these versions are advised to apply the latest security updates to mitigate this risk.

Affected Version(s)

Update Manager Plugin 1.5.0 <= 1.6.0

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.