Description
Dell Update Manager Plugin, version(s) 1.5.0 through 1.6.0, contain(s) an Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information exposure.
No analysis available yet.
Remediation
Vendor Workaround
Sanitization done with user input
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-2775 | Dell Update Manager Plugin, version(s) 1.5.0 through 1.6.0, contain(s) an Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information exposure. |
References
History
Fri, 07 Feb 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 07 Feb 2025 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Dell Update Manager Plugin, version(s) 1.5.0 through 1.6.0, contain(s) an Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information exposure. | |
| Weaknesses | CWE-80 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: dell
Published:
Updated: 2025-02-07T15:58:21.702Z
Reserved: 2025-01-06T13:40:01.388Z
Link: CVE-2025-22402
Updated: 2025-02-07T15:42:50.693Z
Status : Received
Published: 2025-02-07T03:15:12.287
Modified: 2025-02-07T03:15:12.287
Link: CVE-2025-22402
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD