Cross-site Scripting Flaw in Dell Wyse Management Suite
CVE-2025-36580
4.8MEDIUM
What is CVE-2025-36580?
The Dell Wyse Management Suite, prior to version 5.2, is susceptible to an improper neutralization of input during web page generation, commonly known as a Cross-site Scripting (XSS) vulnerability. This flaw allows a high-privileged attacker with remote access to exploit the system, potentially leading to unauthorized script injection. As a result, this vulnerability poses a significant risk to the integrity and security of web applications using the affected suite.
Affected Version(s)
Wyse Management Suite < 5.2
References
CVSS V3.1
Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved