CVE-2019-3747
MEDIUMDell EMC Integrated Data Protection Appliance < 2.3 - Stored Cross-Site Scripting in Cloud DR Add-On Field
Title source: llmDescription
Dell EMC Integrated Data Protection Appliance versions prior to 2.3 contain a stored cross-site scripting vulnerability. A remote malicious ACM admin user may potentially exploit this vulnerability to store malicious HTML or JavaScript code in Cloud DR add-on specific field. When victim users access the page through their browsers, the malicious code gets executed by the web browser in the context of the vulnerable web application.
References (1)
Core 1
Core References
Vendor Advisory x_refsource_confirm
https://www.dell.com/support/security/en-us/details/536363/DSA-2019-112-Dell-EMC-Integrated-Data-Protection-Appliance-Multiple-Vulnerabilities
Scores
CVSS v3
4.8
EPSS
0.0038
EPSS Percentile
59.5%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Details
CWE
CWE-79
Status
published
Products (3)
dell/emc_integrated_data_protection_appliance_firmware
2.0
dell/emc_integrated_data_protection_appliance_firmware
2.1
dell/emc_integrated_data_protection_appliance_firmware
2.2
Published
Sep 27, 2019
Tracked Since
Feb 18, 2026