Dell EMC Unity Operating Environment versions prior to 5.0.0.0.5.116, Dell EMC UnityVSA versions prior to 5.0.0.0.5.116 and Dell EMC VNXe3200 versions prior to 3.1.10.9946299 contain a reflected cross-site scripting vulnerability on the cas/logout page. A remote unauthenticated attacker could potentially exploit this vulnerability by tricking a victim application user to supply malicious HTML or Java Script code to Unisphere, which is then reflected back to the victim and executed by the web browser.
2019-09-03T17:15:11.273
2024-11-21T04:42:28.160
Modified
CVSSv3.0: 4.7 (MEDIUM)
AV:N/AC:M/Au:N/C:N/I:P/A:N
8.6
2.9
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | dell | emc_unity_operating_environment | < 5.0.0.0.5.116 | Yes |
| Application | dell | emc_unityvsa_operating_environment | < 5.0.0.0.5.116 | Yes |
| Operating System | dell | emc_vnxe3200_firmware | < 3.1.10.9946299 | Yes |
| Hardware | dell | emc_vnxe3200 | - | No |