First published: Mon Nov 01 2021(Updated: )
Dell EMC CloudLink 7.1 and all prior versions contain a HTML and Javascript Injection Vulnerability. A remote low privileged attacker, may potentially exploit this vulnerability, directing end user to arbitrary and potentially malicious websites.
Credit: security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
Dell EMC Cloud Link | <7.1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-36332 has a low severity rating due to the requirement for low privileged access and the exploitation method involving redirection.
To fix CVE-2021-36332, upgrade to Dell EMC CloudLink version 7.1.1 or later.
CVE-2021-36332 affects all versions of Dell EMC CloudLink up to and including version 7.1.
CVE-2021-36332 enables HTML and Javascript injection attacks that can redirect users to malicious websites.
Yes, exploitation of CVE-2021-36332 requires user interaction to navigate to the malicious website.