VMware Aria Operations contains a stored cross-site scripting vulnerability. A malicious actor with editing access to cloud provider might be able to inject malicious script leading to stored cross-site scripting in the product VMware Aria Operations.
2024-11-26T12:15:18.900
2025-05-14T16:36:45.747
Analyzed
CVSSv3.1: 6.5 (MEDIUM)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | vmware | aria_operations | < 8.18.2 | Yes |
| Application | vmware | cloud_foundation | ≤ 5.2 | Yes |