Impact
A stored cross‑site scripting flaw in the HPE Networking Fabric Composer management interface lets a logged‑in low‑privilege operator inject malicious script that is saved and later rendered for any administrative user. On execution, the script runs with the victim administrator’s privileges in the browser, enabling data theft, session hijacking, or redirection attacks. The vulnerability does not directly compromise the underlying server, but it can provide attackers a foothold for broader compromises if an administrator’s session is hijacked.
Affected Systems
The affected product is Hewlett Packard Enterprise’s Fabric Composer web‑based management subsystem. No specific firmware or software version ranges are listed in the available data, so all releases of the interface that allow the operator to submit forged input are presumed vulnerable until verified by HPE.
Risk and Exploitability
The CVSS score of 9 indicates a high‑severity vulnerability with high impact. EPSS data is not available, and the issue is not currently listed in the CISA KEV catalog, implying limited evidence of exploitation at this time. However, based on the description, it is inferred that the attack vector is an authenticated low‑privilege operator who submits malicious input through the Fabric Composer web interface. This makes the attack path likely for insiders or compromised accounts. The exploit path involves injecting malicious HTML/JavaScript through form fields or data entries that are later displayed to administrators, so while the probability of exploitation is uncertain, the potential damage warrants prompt remediation.
OpenCVE Enrichment