CVE-2017-4926: XSS
VMware vCenter Server (6.5 prior to 6.5 U1) contains a vulnerability that may allow for stored cross-site scripting (XSS). An attacker with VC user privileges can inject malicious java-scripts which will get executed when other VC users access the page.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2017-4926?
CVE-2017-4926 is classified as a medium severity vulnerability due to the potential for stored cross-site scripting.
How do I fix CVE-2017-4926?
To fix CVE-2017-4926, upgrade VMware vCenter Server to version 6.5 U1 or later.
Who is affected by CVE-2017-4926?
CVE-2017-4926 affects users of VMware vCenter Server version 6.5 before the U1 update.
What is the impact of CVE-2017-4926?
The impact of CVE-2017-4926 allows an attacker with user privileges to inject malicious scripts that execute in the context of other users.
Is CVE-2017-4926 a client-side or server-side vulnerability?
CVE-2017-4926 is a client-side vulnerability as it involves cross-site scripting that executes in users' browsers.