Medium
Summary:
Dell EMC ECS contains remediation for an XSS vulnerability that may potentially be exploited by malicious users to compromise the affected system.
CVE-2020-5317
Dell EMC ECS versions prior to 3.4.0.1 contain an XSS vulnerability. A remote authenticated malicious user may potentially exploit this vulnerability to store malicious HTML or JavaScript code in a trusted application data store. When victim users access the data store through their browsers, the malicious code may get executed by the web browser in the context of the vulnerable web application.
CVSS v3.0 Base Score: 6.2 (AV:N/AC:L/PR:H/UI:R/S:C/C:N/I:H/A:N)
CVE-2020-5317
Dell EMC ECS versions prior to 3.4.0.1 contain an XSS vulnerability. A remote authenticated malicious user may potentially exploit this vulnerability to store malicious HTML or JavaScript code in a trusted application data store. When victim users access the data store through their browsers, the malicious code may get executed by the web browser in the context of the vulnerable web application.
CVSS v3.0 Base Score: 6.2 (AV:N/AC:L/PR:H/UI:R/S:C/C:N/I:H/A:N)
Affected products:
Dell EMC ECS versions prior to 3.4.0.1
Remediation:
The following Dell EMC ECS release addresses this vulnerability:
Dell EMC ECS 3.4.0.1
Dell EMC recommends all customers have their Dell EMC ECS systems upgraded at the earliest opportunity by opening a Dell EMC ECS service request.
Link to Request Upgrade:
https://www.dell.com/support/home
Affected products:
Dell EMC ECS versions prior to 3.4.0.1
Remediation:
The following Dell EMC ECS release addresses this vulnerability:
Dell EMC ECS 3.4.0.1
Dell EMC recommends all customers have their Dell EMC ECS systems upgraded at the earliest opportunity by opening a Dell EMC ECS service request.
Link to Request Upgrade:
https://www.dell.com/support/home
Dell would like to thank Ben Sazgar from Citadel Cyber Security for reporting this issue.