Required CVE Record Information
Description
Dell Wyse Management Suite, versions prior to WMS 5.1, contains an Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Script injection.
CWE 1 Total
CVSS 1 Total
Score | Severity | Version | Vector String |
---|---|---|---|
4.9 | MEDIUM | 3.1 | CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N |
Credits
- Dell Technologies would like to thank Alain Mowat from Orange Cyberdefense Switzerland's research lab for reporting these issues. finder
References 1 Total
- https://www.dell.com/support/kbdoc/en-us/000296515/dsa-2025-135 vendor-advisory