Dell EMC Unity Operating Environment versions prior to 5.0.0.0.5.116, Dell EMC UnityVSA versions prior to 5.0.0.0.5.116 and Dell EMC VNXe3200 versions prior to 3.1.10.9946299 contain a reflected cross-site scripting vulnerability on the cas/logout page. A remote unauthenticated attacker could potentially exploit this vulnerability by tricking a victim application user to supply malicious HTML or Java Script code to Unisphere, which is then reflected back to the victim and executed by the web browser.
References
Information
Published : 2019-09-03 10:15
Updated : 2019-10-09 16:49
NVD link : CVE-2019-3754
Mitre link : CVE-2019-3754
JSON object : View
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Products Affected
dell
- emc_vnxe3200_firmware
- emc_vnxe3200
- emc_unity_operating_environment
- emc_unityvsa_operating_environment