First published: Thu Jul 24 2014(Updated: )
Cross-site scripting (XSS) vulnerability in sgms/panelManager in Dell SonicWALL GMS, Analyzer, and UMA before 7.2 SP1 allows remote attackers to inject arbitrary web script or HTML via the node_id parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
SonicWALL Analyzer | <=7.2 | |
SonicWALL Global Management System | <=7.2 | |
SonicWall UMA EM5000 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-5024 is classified as a medium severity vulnerability due to its potential for cross-site scripting attacks.
To fix CVE-2014-5024, upgrade to SonicWALL GMS, Analyzer, or UMA version 7.2 SP1 or later.
CVE-2014-5024 affects SonicWALL GMS, Analyzer, and UMA versions up to 7.2.
Yes, attackers can exploit CVE-2014-5024 remotely through crafted requests to the affected web interface.
By exploiting CVE-2014-5024, attackers can inject arbitrary web scripts or HTML into the application's interface.