Description
Dell EMC Integrated Data Protection Appliance versions prior to 2.3 contain a stored cross-site scripting vulnerability. A remote malicious ACM admin user may potentially exploit this vulnerability to store malicious HTML or JavaScript code in Cloud DR add-on specific field. When victim users access the page through their browsers, the malicious code gets executed by the web browser in the context of the vulnerable web application.
Published: 2019-09-27
Score: 4.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2019-13382 Dell EMC Integrated Data Protection Appliance versions prior to 2.3 contain a stored cross-site scripting vulnerability. A remote malicious ACM admin user may potentially exploit this vulnerability to store malicious HTML or JavaScript code in Cloud DR add-on specific field. When victim users access the page through their browsers, the malicious code gets executed by the web browser in the context of the vulnerable web application.
History

No history.

Subscriptions

Dell Emc Idpa Dp4400 Emc Idpa Dp5800 Emc Idpa Dp8300 Emc Idpa Dp8800 Emc Integrated Data Protection Appliance Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2024-09-17T00:26:31.837Z

Reserved: 2019-01-03T00:00:00.000Z

Link: CVE-2019-3747

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2019-09-27T21:15:10.207

Modified: 2024-11-21T04:42:27.437

Link: CVE-2019-3747

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses