Dell EMC Isilon versions between 8.1.0.0 - 8.1.0.1, 8.0.1.0 - 8.0.1.2, and 8.0.0.0 - 8.0.0.6, and version 7.1.1.11 is affected by a cross-site scripting vulnerability in the NDMP Page within the OneFS web administration interface. A malicious administrator may potentially inject arbitrary HTML or JavaScript code in the user's browser session in the context of the OneFS website.
2018-03-26T18:29:01.190
2024-11-21T03:59:23.163
Modified
CVSSv3.0: 4.8 (MEDIUM)
AV:N/AC:M/Au:S/C:N/I:P/A:N
6.8
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | dell | emc_isilon | ≤ 8.0.0.6 | Yes |
Application | dell | emc_isilon | ≤ 8.0.1.2 | Yes |
Application | dell | emc_isilon | ≤ 8.1.0.1 | Yes |
Application | dell | emc_isilon | 7.1.1.11 | Yes |