CVE-2016-6641: XSS
Published Sep 18, 2016
·Updated
Cross-site scripting (XSS) vulnerability in EMC ViPR SRM before 3.7.2 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
Affected Software
1 affected component
EMC ViPR SRM<=3.7.1
Event History
Sep 18, 2016
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-6641?
CVE-2016-6641 is classified as a medium severity vulnerability due to its potential impact on user data and integrity.
2
How do I fix CVE-2016-6641?
To fix CVE-2016-6641, upgrade to EMC ViPR SRM version 3.7.2 or later.
3
What impact does CVE-2016-6641 have on my system?
CVE-2016-6641 allows remote authenticated users to perform cross-site scripting attacks, potentially compromising the web application.
4
Is CVE-2016-6641 easy to exploit?
CVE-2016-6641 can be exploited by authenticated users, making it moderately easy to leverage in environments with inadequate access controls.
5
Who is affected by CVE-2016-6641?
CVE-2016-6641 affects all versions of EMC ViPR SRM prior to 3.7.2, allowing exploitation by authenticated users.