CVE-2018-1188: XSS
Dell EMC Isilon versions between 8.1.0.0 - 8.1.0.1, 8.0.1.0 - 8.0.1.2, and 8.0.0.0 - 8.0.0.6, and versions 7.2.1.x is affected by a cross-site scripting vulnerability in the Authorization Providers page within the OneFS web administration interface. A malicious administrator may potentially inject arbitrary HTML or JavaScript code in the user's browser session in the context of the OneFS website.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-1188?
CVE-2018-1188 is a cross-site scripting vulnerability in the Authorization Providers page within the Dell EMC Isilon OneFS web administration interface.
Which versions of Dell EMC Isilon are affected by CVE-2018-1188?
Dell EMC Isilon versions 7.2.1.x, 8.0.0.0 - 8.0.0.6, 8.0.1.0 - 8.0.1.2, and 8.1.0.0 - 8.1.0.1 are affected by CVE-2018-1188.
What is the severity of CVE-2018-1188?
The severity of CVE-2018-1188 is rated as medium.
How can a malicious administrator exploit CVE-2018-1188?
A malicious administrator can potentially inject a cross-site scripting payload.
Are there any references available for CVE-2018-1188?
Yes, you can find references for CVE-2018-1188 at the following links: [link1](http://seclists.org/fulldisclosure/2018/Mar/50), [link2](http://www.securityfocus.com/bid/103033), [link3](https://www.coresecurity.com/advisories/dell-emc-isilon-onefs-multiple-vulnerabilities).