CVE-2018-1202
MEDIUMDell Emc Isilon < 8.0.0.6 - XSS
Title source: ruleDescription
Dell EMC Isilon versions between 8.1.0.0 - 8.1.0.1, 8.0.1.0 - 8.0.1.2, and 8.0.0.0 - 8.0.0.6, and version 7.1.1.11 is affected by a cross-site scripting vulnerability in the NDMP Page within the OneFS web administration interface. A malicious administrator may potentially inject arbitrary HTML or JavaScript code in the user's browser session in the context of the OneFS website.
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by Core Security · textwebappslinux
https://www.exploit-db.com/exploits/44039
References (4)
Scores
CVSS v3
4.8
EPSS
0.0216
EPSS Percentile
84.0%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Classification
CWE
CWE-79
Status
published
Affected Products (2)
dell/emc_isilon
< 8.0.0.6
dell/emc_isilon
Timeline
Published
Mar 26, 2018
Tracked Since
Feb 18, 2026