CVE-2025-22402: XSS
Published Feb 7, 2025
·Updated
Dell Update Manager Plugin, version(s) 1.5.0 through 1.6.0, contain(s) an Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information exposure.
Affected Software
2 affected components
Dell Update Manager Plugin>=1.5.0<=1.6.0
Dell Update Manager Plugin>=1.5.0<1.7.0
Event History
Feb 7, 2025
CVE Published
via MITRE·02:08 AM
Data Sourced
via MITRE·02:08 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-22402?
CVE-2025-22402 is classified as a low-severity vulnerability.
2
How do I fix CVE-2025-22402?
To fix CVE-2025-22402, update the Dell Update Manager Plugin to version 1.6.1 or later.
3
What are the implications of exploiting CVE-2025-22402?
Exploitation of CVE-2025-22402 could lead to information exposure for low privileged attackers with remote access.
4
Which versions of Dell Update Manager Plugin are affected by CVE-2025-22402?
CVE-2025-22402 affects Dell Update Manager Plugin versions 1.5.0 through 1.6.0.
5
Is remote access required for exploiting CVE-2025-22402?
Yes, remote access is necessary for an attacker to exploit CVE-2025-22402.