9

CVE-2021-21515

Dell EMC SourceOne, versions 7.2SP10 and prior, contain a Stored Cross-Site Scripting vulnerability. A remote low privileged attacker may potentially exploit this vulnerability, to hijack user sessions or to trick a victim application user to unknowingly send arbitrary requests to the server.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
DellEmc Sourceone Version < 7.2
DellEmc Sourceone Version7.2 Update-
DellEmc Sourceone Version7.2 Updatesp1
DellEmc Sourceone Version7.2 Updatesp2
DellEmc Sourceone Version7.2 Updatesp3
DellEmc Sourceone Version7.2 Updatesp4
DellEmc Sourceone Version7.2 Updatesp5
DellEmc Sourceone Version7.2 Updatesp6
DellEmc Sourceone Version7.2 Updatesp7
DellEmc Sourceone Version7.2 Updatesp8
DellEmc Sourceone Version7.2 Updatesp9
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.26% 0.461
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5.4 2.3 2.7
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
nvd@nist.gov 3.5 6.8 2.9
AV:N/AC:M/Au:S/C:N/I:P/A:N
security_alert@emc.com 9 2.3 6
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.