← back
CVE-2020-5317

CVE-2020-5317

CVSS 6.2 MEDIUMEPSS 0.6%CWE-79
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 6.2EPSS 0.6%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
06 Feb 2020Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
Dell EMC ECS versions prior to 3.4.0.1 contain an XSS vulnerability. A remote authenticated malicious user could exploit this vulnerability to store malicious HTML or JavaScript code in a trusted application data store. When victim users access the data store through their browsers, the malicious code gets executed by the web browser in the context of the vulnerable web application.
CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:C/C:N/I:H/A:N

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →