CVE-2021-21515

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
01/03/2021
Last modified:
08/03/2021

Description

Dell EMC SourceOne, versions 7.2SP10 and prior, contain a Stored Cross-Site Scripting vulnerability. A remote low privileged attacker may potentially exploit this vulnerability, to hijack user sessions or to trick a victim application user to unknowingly send arbitrary requests to the server.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:dell:emc_sourceone:*:*:*:*:*:*:*:* 7.2 (excluding)
cpe:2.3:a:dell:emc_sourceone:7.2:-:*:*:*:*:*:*
cpe:2.3:a:dell:emc_sourceone:7.2:sp1:*:*:*:*:*:*
cpe:2.3:a:dell:emc_sourceone:7.2:sp2:*:*:*:*:*:*
cpe:2.3:a:dell:emc_sourceone:7.2:sp3:*:*:*:*:*:*
cpe:2.3:a:dell:emc_sourceone:7.2:sp4:*:*:*:*:*:*
cpe:2.3:a:dell:emc_sourceone:7.2:sp5:*:*:*:*:*:*
cpe:2.3:a:dell:emc_sourceone:7.2:sp6:*:*:*:*:*:*
cpe:2.3:a:dell:emc_sourceone:7.2:sp7:*:*:*:*:*:*
cpe:2.3:a:dell:emc_sourceone:7.2:sp8:*:*:*:*:*:*
cpe:2.3:a:dell:emc_sourceone:7.2:sp9:*:*:*:*:*:*