Dell EMC Integrated Data Protection Appliance versions prior to 2.3 contain a stored cross-site scripting vulnerability. A remote malicious ACM admin user may potentially exploit this vulnerability to store malicious HTML or JavaScript code in Cloud DR add-on specific field. When victim users access the page through their browsers, the malicious code gets executed by the web browser in the context of the vulnerable web application.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published: 2019-09-27T20:21:21.014325Z

Updated: 2024-09-17T00:26:31.837Z

Reserved: 2019-01-03T00:00:00

Link: CVE-2019-3747

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2019-09-27T21:15:10.207

Modified: 2019-10-09T23:49:34.790

Link: CVE-2019-3747

cve-icon Redhat

No data.