Impact
A reflected Cross‑Site Scripting flaw exists in the report detail page of WatchGuard Dimension. The flaw allows an attacker to embed a malicious JavaScript payload in a specially crafted URL. When an authenticated user clicks the URL, the script executes in the victim's browser context, giving the attacker the same privileges as the user. The vulnerability is classified as CWE‑79 and could lead to session hijacking, data theft, or defacement of the authenticated user's view.
Affected Systems
All deployed instances of WatchGuard Dimension running a version older than 2.3.1 are affected. Users of the latest patched release, 2.3.1, are not vulnerable. The issue manifests on the report detail page, which is accessible to any authenticated user who can request a report view.
Risk and Exploitability
The CVSS score of 4.6 places the vulnerability in the moderate range. EPSS data is not available, and the flaw is not listed in the CISA KEV catalog. Exploitation requires the victim to be logged in to Dimension and to click a malicious URL crafted by the attacker. Thus, the likelihood of remote exploitation is low to moderate, but within an organization that hosts internal users, the risk rises because authenticated users may be unknowingly tricked into executing the payload. The impact is high if the attacker succeeds, as the script runs with the victim’s browser privileges.
OpenCVE Enrichment