CVE-2021-21515

CRITICAL

Dell EMC SourceOne < 7.2SP10 - Stored Cross-Site Scripting

Title source: llm
STIX 2.1

Description

Dell EMC SourceOne, versions 7.2SP10 and prior, contain a Stored Cross-Site Scripting vulnerability. A remote low privileged attacker may potentially exploit this vulnerability, to hijack user sessions or to trick a victim application user to unknowingly send arbitrary requests to the server.

Scores

CVSS v3 9.0
EPSS 0.0020
EPSS Percentile 41.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H

Details

CWE
CWE-79
Status published
Products (2)
dell/emc_sourceone 7.2 (10 CPE variants)
dell/emc_sourceone < 7.2
Published Mar 01, 2021
Tracked Since Feb 18, 2026