CVE-2018-1186

MEDIUM

Dell EMC Isilon - XSS

Title source: llm

Description

Dell EMC Isilon versions between 8.1.0.0 - 8.1.0.1, 8.0.1.0 - 8.0.1.2, and 8.0.0.0 - 8.0.0.6, versions 7.2.1.x, and version 7.1.1.11 is affected by a cross-site scripting vulnerability in the Cluster description of the OneFS web administration interface. A malicious administrator may potentially inject arbitrary HTML or JavaScript code in the user's browser session in the context of the OneFS website.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Core Security · textwebappslinux
https://www.exploit-db.com/exploits/44039

Scores

CVSS v3 4.8
EPSS 0.0216
EPSS Percentile 84.0%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N

Classification

CWE
CWE-79
Status published

Affected Products (2)

dell/emc_isilon < 7.2.1.6
dell/emc_isilon

Timeline

Published Mar 26, 2018
Tracked Since Feb 18, 2026