First published: Wed May 11 2022(Updated: )
Dell Unity, Dell UnityVSA, and Dell UnityXT versions prior to 5.2.0.0.5.173 contain a Reflected Cross-Site Scripting Vulnerability in Unisphere GUI. An Unauthenticated Remote Attacker could potentially exploit this vulnerability, leading to the execution of malicious HTML or JavaScript code in a victim user's web browser in the context of the vulnerable web application. Exploitation may lead to information disclosure, session theft, or client-side request forgery.
Credit: security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
Dell Unity Operating Environment | <5.2.0.0.5.173 | |
Dell Unity Xt Operating Environment | <5.2.0.0.5.173 | |
Dell Unityvsa Operating Environment | <5.2.0.0.5.173 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-29091 is a Reflected Cross-Site Scripting vulnerability found in Dell Unity, Dell UnityVSA, and Dell UnityXT versions prior to 5.2.0.0.5.173.
CVE-2022-29091 affects Dell Unity, Dell UnityVSA, and Dell UnityXT versions prior to 5.2.0.0.5.173.
CVE-2022-29091 has a severity level of medium with a CVSS score of 6.1.
An unauthenticated remote attacker could potentially exploit CVE-2022-29091 by executing malicious HTML or JavaScript code in a victim's browser through the Unisphere GUI.
To fix CVE-2022-29091, users should upgrade to Dell Unity, Dell UnityVSA, and Dell UnityXT version 5.2.0.0.5.173 or later.