Cross-site Scripting Vulnerability in Dell Wyse Management Suite
CVE-2025-27693

4.9MEDIUM

Key Information:

Vendor
Dell
Vendor
CVE Published:
2 April 2025

Summary

The Dell Wyse Management Suite prior to version 5.1 has a vulnerability that allows for improper neutralization of input during web page generation, specifically a cross-site scripting (XSS) issue. This security flaw could permit attackers with high privileges and remote access to manipulate web pages, leading to the potential execution of malicious scripts within user browsers. Organizations using affected versions are encouraged to update to the latest version to mitigate risks.

Affected Version(s)

Wyse Management Suite < 5.1

References

CVSS V3.1

Score:
4.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.