Impact
This vulnerability is a stored cross‑site scripting flaw in the Backup Historical Data feature of WatchGuard Dimension. An authenticated administrator can embed arbitrary JavaScript into historical data entries, and when other users view that data the script executes in their browser. Because the code runs with the victim’s privileges, it can steal session cookies, capture credentials, or perform actions on the user’s behalf. The weakness is classified as CWE‑79.
Affected Systems
All versions of WatchGuard Dimension that have not been upgraded to the patched release 2.3.1 are susceptible. The flaw is triggered through the Backup Historical Data interface, which is available to any user with administrator rights.
Risk and Exploitability
The CVSS score of 5.1 reflects a moderate severity; an EPSS score is not supplied and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires an authenticated administrator account, limiting the initial attack surface to privileged users. Once an attacker creates or modifies a malicious entry, any other user who views that data in a web browser is exposed to the injected script. The likely attack vector is internal, relying on administrative access, and the potential impact includes session hijacking, data theft, or further privilege escalation within the affected system.
OpenCVE Enrichment