Cross-site Scripting Vulnerability in Dell Storage Manager
CVE-2025-23379

5.2MEDIUM

Key Information:

Vendor

Dell

Vendor
CVE Published:
6 May 2025

What is CVE-2025-23379?

Dell Storage Manager, particularly version 21.0.20, is susceptible to a cross-site scripting vulnerability due to improper input handling during web page generation. This flaw can be exploited by unauthenticated attackers who have adjacent network access, potentially leading to unauthorized script injection activities. Such vulnerabilities underscore the importance of securing web applications against malicious inputs and maintaining up-to-date software to mitigate risks.

Affected Version(s)

Dell Storage Center - Dell Storage Manager < 2020 R1.21

References

CVSS V3.1

Score:
5.2
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Dell would like to thank redfr0g for reporting this issue.
.
CVE-2025-23379 : Cross-site Scripting Vulnerability in Dell Storage Manager