Cross-site Scripting Flaw in Dell Wyse Management Suite
CVE-2025-36580

6.1MEDIUM

Key Information:

Vendor

Dell

Vendor
CVE Published:
10 June 2025

What is CVE-2025-36580?

The Dell Wyse Management Suite, prior to version 5.2, is susceptible to an improper neutralization of input during web page generation, commonly known as a Cross-site Scripting (XSS) vulnerability. This flaw allows a high-privileged attacker with remote access to exploit the system, potentially leading to unauthorized script injection. As a result, this vulnerability poses a significant risk to the integrity and security of web applications using the affected suite.

Affected Version(s)

Wyse Management Suite < 5.2

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.