First published: Fri Sep 15 2017(Updated: )
VMware vCenter Server (6.5 prior to 6.5 U1) contains a vulnerability that may allow for stored cross-site scripting (XSS). An attacker with VC user privileges can inject malicious java-scripts which will get executed when other VC users access the page.
Credit: security@vmware.com
Affected Software | Affected Version | How to fix |
---|---|---|
VMware vCenter | =6.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-4926 is classified as a medium severity vulnerability due to the potential for stored cross-site scripting.
To fix CVE-2017-4926, upgrade VMware vCenter Server to version 6.5 U1 or later.
CVE-2017-4926 affects users of VMware vCenter Server version 6.5 before the U1 update.
The impact of CVE-2017-4926 allows an attacker with user privileges to inject malicious scripts that execute in the context of other users.
CVE-2017-4926 is a client-side vulnerability as it involves cross-site scripting that executes in users' browsers.