Medium severity4.7NVD Advisory· Published Sep 28, 2018· Updated Jun 17, 2026
CVE-2018-1246
CVE-2018-1246
Description
Dell EMC Unity and UnityVSA contains reflected cross-site scripting vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability by tricking a victim application user to supply malicious HTML or Java Script code to Unisphere, which is then reflected back to the victim and executed by the web browser.
Affected products
6- cpe:2.3:a:dell:emc_unity_operating_environment:*:*:*:*:*:*:*:*Range: <4.3.1.1525703027
- cpe:2.3:a:dell:emc_unityvsa_operating_environment:*:*:*:*:*:*:*:*Range: <4.3.1.1525703027
Patches
Vulnerability mechanics
References
1- seclists.org/fulldisclosure/2018/Sep/30nvdMailing ListThird Party Advisory
News mentions
0No linked articles in our index yet.