CVE-2022-33934

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
10/02/2023
Last modified:
07/11/2023

Description

<br /> Dell PowerScale OneFS, versions 8.2.x through 9.4.x contain multiple stored cross-site scripting vulnerabilities. A remote authenticated malicious user with high privileges may potentially exploit these vulnerabilities to store malicious HTML or JavaScript code through multiple affected fields.<br /> <br /> <br /> <br /> <br /> <br />

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:dell:emc_powerscale_onefs:*:*:*:*:*:*:*:* 9.1.0.0 (including) 9.1.0.23 (including)
cpe:2.3:o:dell:emc_powerscale_onefs:*:*:*:*:*:*:*:* 9.2.1.0 (including) 9.2.1.16 (including)
cpe:2.3:o:dell:emc_powerscale_onefs:*:*:*:*:*:*:*:* 9.3.0.0 (including) 9.3.0.7 (including)
cpe:2.3:o:dell:emc_powerscale_onefs:*:*:*:*:*:*:*:* 9.4.0.0 (including) 9.4.0.4 (including)


References to Advisories, Solutions, and Tools