VMware Aria Operations contains a stored cross-site scripting vulnerability. A malicious actor with editing access to email templates might inject malicious script leading to stored cross-site scripting in the product VMware Aria Operations.
2024-11-26T12:15:18.800
2025-05-14T16:36:49.860
Analyzed
CVSSv3.1: 6.8 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | vmware | aria_operations | < 8.18.2 | Yes |
Application | vmware | cloud_foundation | ≤ 5.2 | Yes |