Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2025-23377


Dell PowerProtect Data Manager Reporting, version(s) 19.17, 19.18 contain(s) an Improper Encoding or Escaping of Output vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability to inject arbitrary web script or html in reporting outputs.


Published

2025-04-28T15:15:45.437

Last Modified

2025-05-13T13:25:00.880

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 4.2 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-116

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application dell powerprotect_data_manager 19.17 Yes
Application dell powerprotect_data_manager 19.18 Yes

References