← Back

CVE-2023-44286

nvd nist
Published: Dec 14, 2023Modified: Nov 21, 2024

JSON object

Loading...
6.1
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.8 / Impact: 2.7
Source: NVD

Description

Dell PowerProtect DD , versions prior to 7.13.0.10, LTS 7.7.5.25, LTS 7.10.1.15, 6.2.1.110 contain a DOM-based Cross-Site Scripting vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to the injection of malicious HTML or JavaScript code to a victim user's DOM environment in the browser. . Exploitation may lead to information disclosure, session theft, or client-side request forgery.

Affected (13)

5 products
Powerprotect Data Protection
Apex Protection Storage
Emc Data Domain Os
Powerprotect Data Domain
Configuration A
1 vulnerable · 2 platform
Vulnerable SoftwareAffected Versions
Before 2.7.6
Running on/withPlatform Versions
Dell
Dp4400
All versions
Dell
Dp5900
All versions
Configuration B
12 vulnerable · 5 platform
Vulnerable SoftwareAffected Versions
Dell
Before 6.2.1.110
From 7.0 to 7.10.1.15
Dell
Before 6.2.1.110
From 7.0 to 7.12.0.0
From 7.7 to 7.7.5.25
From 7.10 to 7.10.1.15
Dell
Before 6.2.1.110
From 7.0 to 7.12.0.0
Dell
Before 6.2.1.110
From 7.0 to 7.13.0.10
From 7.7 to 7.7.5.25
From 7.10 to 7.10.1.15
Running on/withPlatform Versions
Dell
Dd3300
All versions
Dell
Dd6400
All versions
Dell
Dd6900
All versions
Dell
Dd9400
All versions
Dell
Dd9900
All versions

Timeline

No history available yet.