CVE-2018-1202: XSS
Dell EMC Isilon versions between 8.1.0.0 - 8.1.0.1, 8.0.1.0 - 8.0.1.2, and 8.0.0.0 - 8.0.0.6, and version 7.1.1.11 is affected by a cross-site scripting vulnerability in the NDMP Page within the OneFS web administration interface. A malicious administrator may potentially inject arbitrary HTML or JavaScript code in the user's browser session in the context of the OneFS website.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-1202?
CVE-2018-1202 is a cross-site scripting vulnerability in the NDMP Page within the OneFS web administration interface of Dell EMC Isilon versions 8.1.0.0 - 8.1.0.1, 8.0.1.0 - 8.0.1.2, and 8.0.0.0 - 8.0.0.6, as well as version 7.1.1.11.
What is the severity of CVE-2018-1202?
CVE-2018-1202 has a severity level of medium with a rating of 4.8.
Which software versions are affected by CVE-2018-1202?
Dell EMC Isilon versions 8.1.0.0 - 8.1.0.1, 8.0.1.0 - 8.0.1.2, and 8.0.0.0 - 8.0.0.6, as well as version 7.1.1.11, are affected by CVE-2018-1202.
How can a malicious administrator exploit CVE-2018-1202?
A malicious administrator can exploit CVE-2018-1202 by injecting arbitrary HTML or JavaScript code through the NDMP Page of Dell EMC Isilon's OneFS web administration interface.
Are there any references for more information about CVE-2018-1202?
Yes, you can find more information about CVE-2018-1202 at the following references: [http://seclists.org/fulldisclosure/2018/Mar/50](http://seclists.org/fulldisclosure/2018/Mar/50), [http://www.securityfocus.com/bid/103033](http://www.securityfocus.com/bid/103033), and [https://www.coresecurity.com/advisories/dell-emc-isilon-onefs-multiple-vulnerabilities](https://www.coresecurity.com/advisories/dell-emc-isilon-onefs-multiple-vulnerabilities).