Dell SmartFabric Storage Software v1.4 (and earlier) contains possible vulnerabilities for HTML injection or CVS formula injection which might escalate to cross-site scripting attacks in HTML pages in the GUI. A remote authenticated attacker could potentially exploit these issues, leading to various injection type attacks.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 19 Sep 2024 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2024-09-19T18:48:48.616Z

Reserved: 2023-09-15T07:00:32.006Z

Link: CVE-2023-43071

cve-icon Vulnrichment

Updated: 2024-08-02T19:37:23.000Z

cve-icon NVD

Status : Modified

Published: 2023-10-05T18:15:12.347

Modified: 2024-11-21T08:23:40.637

Link: CVE-2023-43071

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.