First published: Mon Mar 26 2018(Updated: )
Dell EMC Isilon versions between 8.1.0.0 - 8.1.0.1, 8.0.1.0 - 8.0.1.2, and 8.0.0.0 - 8.0.0.6, versions 7.2.1.x, and version 7.1.1.11 is affected by a cross-site scripting vulnerability in the Cluster description of the OneFS web administration interface. A malicious administrator may potentially inject arbitrary HTML or JavaScript code in the user's browser session in the context of the OneFS website.
Credit: security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
Dell EMC Isilon | >=7.2.1.0<=7.2.1.6 | |
Dell EMC Isilon | >=8.0.0.0<=8.0.0.6 | |
Dell EMC Isilon | >=8.0.1.0<=8.0.1.2 | |
Dell EMC Isilon | >=8.1.0.0<=8.1.0.1 | |
Dell EMC Isilon | =7.1.1.11 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2018-1186 is medium with a score of 4.8.
Dell EMC Isilon versions between 8.1.0.0 - 8.1.0.1, 8.0.1.0 - 8.0.1.2, 8.0.0.0 - 8.0.0.6, 7.2.1.x, and 7.1.1.11 are affected by CVE-2018-1186.
CVE-2018-1186 is a cross-site scripting vulnerability in the Cluster description of the OneFS web administration interface in Dell EMC Isilon.
A malicious administrator can potentially inject arbitrary web script or HTML via the Cluster description field in the OneFS web administration interface, allowing for script execution in the context of an authenticated administrator session.
Yes, you can find more information about CVE-2018-1186 at the following references: - [http://seclists.org/fulldisclosure/2018/Mar/50](http://seclists.org/fulldisclosure/2018/Mar/50) - [http://www.securityfocus.com/bid/103033](http://www.securityfocus.com/bid/103033) - [https://www.coresecurity.com/advisories/dell-emc-isilon-onefs-multiple-vulnerabilities](https://www.coresecurity.com/advisories/dell-emc-isilon-onefs-multiple-vulnerabilities)