CVE-2013-7025: XSS
Multiple cross-site scripting (XSS) vulnerabilities in ematStaticAlertTypes.jsp in the Alert Settings section in Dell SonicWALL Global Management System (GMS), Analyzer, and UMA EM5000 7.1 SP1 before Hotfix 134235 allow remote authenticated users to inject arbitrary web script or HTML via the (1) valfield1 or (2) value1 parameter to createNewThreshold.jsp.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Dell SonicWALL Global Management System (GMS) / Analyzer / UMA EM5000to a version that resolves this vulnerability.Fixed in 7.1 SP1 before Hotfix 134235Patch 134235
Event History
Frequently Asked Questions
What is the severity of CVE-2013-7025?
CVE-2013-7025 is classified as a medium severity vulnerability due to its potential for cross-site scripting (XSS) attacks.
How do I fix CVE-2013-7025?
To fix CVE-2013-7025, upgrade to Dell SonicWALL Global Management System, Analyzer, or UMA EM5000 version 7.1 SP1 with Hotfix 134235 or later.
Which software is affected by CVE-2013-7025?
CVE-2013-7025 affects SonicWALL Analyzer and Global Management System versions 7.0 and 7.1, as well as UMA EM5000 firmware versions 7.0 and 7.1.
Who can exploit CVE-2013-7025?
CVE-2013-7025 can be exploited by remote authenticated users, enabling them to inject arbitrary web scripts or HTML.
What type of vulnerability is CVE-2013-7025?
CVE-2013-7025 is a multiple cross-site scripting (XSS) vulnerability that allows for injection of malicious scripts.