Dell PowerProtect DD , versions prior to 7.13.0.10, LTS 7.7.5.25, LTS 7.10.1.15, 6.2.1.110 contain a DOM-based Cross-Site Scripting vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to the injection of malicious HTML or JavaScript code to a victim user's DOM environment in the browser. . Exploitation may lead to information disclosure, session theft, or client-side request forgery.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Dell
Subscribe
|
Apex Protection Storage
Subscribe
Dd3300
Subscribe
Dd6400
Subscribe
Dd6900
Subscribe
Dd9400
Subscribe
Dd9900
Subscribe
Dp4400
Subscribe
Dp5900
Subscribe
Emc Data Domain Os
Subscribe
Powerprotect Data Domain
Subscribe
Powerprotect Data Domain Management Center
Subscribe
Powerprotect Data Protection
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-48642 | Dell PowerProtect DD , versions prior to 7.13.0.10, LTS 7.7.5.25, LTS 7.10.1.15, 6.2.1.110 contain a DOM-based Cross-Site Scripting vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to the injection of malicious HTML or JavaScript code to a victim user's DOM environment in the browser. . Exploitation may lead to information disclosure, session theft, or client-side request forgery. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: dell
Published:
Updated: 2024-08-02T19:59:52.026Z
Reserved: 2023-09-28T09:25:45.714Z
Link: CVE-2023-44286
No data.
Status : Modified
Published: 2023-12-14T16:15:48.200
Modified: 2024-11-21T08:25:35.523
Link: CVE-2023-44286
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD