CVE-2018-1189: XSS
Dell EMC Isilon versions between 8.1.0.0 - 8.1.0.1, 8.0.1.0 - 8.0.1.2, and 8.0.0.0 - 8.0.0.6, versions 7.2.1.x, and version 7.1.1.11 is affected by a cross-site scripting vulnerability in the Antivirus Page within the OneFS web administration interface. A malicious administrator may potentially inject arbitrary HTML or JavaScript code in the user's browser session in the context of the OneFS website.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-1189?
CVE-2018-1189 is a cross-site scripting vulnerability in the Antivirus Page within the Dell EMC Isilon OneFS web administration interface.
Which versions of Dell EMC Isilon are affected by CVE-2018-1189?
The affected versions of Dell EMC Isilon include 8.1.0.0 - 8.1.0.1, 8.0.1.0 - 8.0.1.2, 8.0.0.0 - 8.0.0.6, 7.2.1.x, and 7.1.1.11.
What is the severity of CVE-2018-1189?
The severity of CVE-2018-1189 is rated as medium, with a CVSS score of 4.8.
How can this vulnerability be exploited?
This vulnerability can be exploited by a malicious administrator injecting malicious code into the Antivirus Page of the OneFS web administration interface.
Are there any references for more information about CVE-2018-1189?
Yes, you can find more information about CVE-2018-1189 at the following references: http://seclists.org/fulldisclosure/2018/Mar/50, http://www.securityfocus.com/bid/103033, and https://www.coresecurity.com/advisories/dell-emc-isilon-onefs-multiple-vulnerabilities.