Impact
The vulnerability is an improper neutralization of input during web page generation. An attacker with low privileges and remote access could inject malicious scripts into the web interface, enabling victim interaction to steal session tokens or perform unauthorized actions. The flaw exists in versions before Dell Wyse Management Suite 5.5 and could compromise confidentiality and integrity of data exposed through the web application.
Affected Systems
Dell Wyse Management Suite installations running versions prior to 5.5, including 5.4 and earlier releases commonly used for thin‑client management in enterprise environments.
Risk and Exploitability
The CVSS score of 5.4 indicates moderate severity and the EPSS score is less than 1%, implying that exploitation is currently unlikely. It has not been listed in CISA's Known Exploited Vulnerabilities catalog. Based on the description, an attacker would need low‑level remote access to the web interface, which is normally granted to system administrators or support personnel. Once authenticated, the attacker could inject scripts via unsanitized parameters to capture victim sessions, redirect users, or execute arbitrary client‑side actions.
OpenCVE Enrichment