CVE-2020-5317

MEDIUM

Dell EMC ECS < 3.4.0.1 - Authenticated Stored Cross-Site Scripting

Title source: llm
STIX 2.1

Description

Dell EMC ECS versions prior to 3.4.0.1 contain an XSS vulnerability. A remote authenticated malicious user could exploit this vulnerability to store malicious HTML or JavaScript code in a trusted application data store. When victim users access the data store through their browsers, the malicious code gets executed by the web browser in the context of the vulnerable web application.

Scores

CVSS v3 4.8
EPSS 0.0021
EPSS Percentile 42.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (1)
dell/emc_elastic_cloud_storage < 3.4.0.1
Published Feb 06, 2020
Tracked Since Feb 18, 2026