CVE-2023-44286: XSS
Dell PowerProtect DD , versions prior to 7.13.0.10, LTS 7.7.5.25, LTS 7.10.1.15, 6.2.1.110 contain a DOM-based Cross-Site Scripting vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to the injection of malicious HTML or JavaScript code to a victim user's DOM environment in the browser. . Exploitation may lead to information disclosure, session theft, or client-side request forgery.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-44286?
CVE-2023-44286 is classified as a high severity DOM-based Cross-Site Scripting vulnerability.
How do I fix CVE-2023-44286?
To fix CVE-2023-44286, update Dell PowerProtect DD and related products to the versions 7.13.0.10 or later, LTS 7.7.5.25, or LTS 7.10.1.15.
Who is affected by CVE-2023-44286?
CVE-2023-44286 affects users of Dell PowerProtect DD prior to 7.13.0.10 and multiple Dell products below specified versions.
What types of attacks could CVE-2023-44286 enable?
CVE-2023-44286 could enable remote unauthenticated attackers to inject malicious HTML or JavaScript code.
Is user authentication required to exploit CVE-2023-44286?
No, CVE-2023-44286 can be exploited by remote unauthenticated attackers.