CVE-2021-36332

MEDIUM

Dell EMC CloudLink < 7.1.1 - HTML and JavaScript Injection

Title source: llm
STIX 2.1

Description

Dell EMC CloudLink 7.1 and all prior versions contain a HTML and Javascript Injection Vulnerability. A remote low privileged attacker, may potentially exploit this vulnerability, directing end user to arbitrary and potentially malicious websites.

References (1)

Core 1

Scores

CVSS v3 5.4
EPSS 0.0011
EPSS Percentile 29.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

Details

CWE
CWE-601
Status published
Products (1)
dell/emc_cloud_link < 7.1.1
Published Nov 23, 2021
Tracked Since Feb 18, 2026