Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2013-7025


Multiple cross-site scripting (XSS) vulnerabilities in ematStaticAlertTypes.jsp in the Alert Settings section in Dell SonicWALL Global Management System (GMS), Analyzer, and UMA EM5000 7.1 SP1 before Hotfix 134235 allow remote authenticated users to inject arbitrary web script or HTML via the (1) valfield_1 or (2) value_1 parameter to createNewThreshold.jsp.


Published

2013-12-09T16:36:50.723

Last Modified

2025-04-11T00:51:21.963

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 3.5 (LOW)

CVSSv2 Vector

AV:N/AC:M/Au:S/C:N/I:P/A:N

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: SINGLE
  • Confidentiality Impact: NONE
  • Integrity Impact: PARTIAL
  • Availability Impact: NONE
Exploitability Score

6.8

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-79

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application sonicwall analyzer 7.0 Yes
Application sonicwall analyzer 7.1 Yes
Application sonicwall analyzer 7.1 Yes
Application sonicwall global_management_system 7.0 Yes
Application sonicwall global_management_system 7.1 Yes
Application sonicwall global_management_system 7.1 Yes
Operating System sonicwall uma_e5000_firmware 7.0 Yes
Operating System sonicwall uma_e5000_firmware 7.1 Yes
Operating System sonicwall uma_e5000_firmware 7.1 Yes
Hardware sonicwall uma_e5000 - No

References