VYPR
Medium severity5.4NVD Advisory· Published Jun 16, 2026· Updated Jun 16, 2026

CVE-2024-30476

CVE-2024-30476

Description

A stored XSS vulnerability in Dell PowerStore Manager allows remote authenticated low-privileged users to execute arbitrary JavaScript in victim browsers.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A stored XSS vulnerability in Dell PowerStore Manager allows remote authenticated low-privileged users to execute arbitrary JavaScript in victim browsers.

Vulnerability

A stored cross-site scripting (XSS) vulnerability exists in the PowerStore Manager web interface of Dell PowerStore (PowerStoreT OS) versions prior to 4.0.0.0-2284811 [1]. The flaw allows a remote authenticated attacker with low privileges to inject malicious scripts into the application, which are then stored and later served to other users [1].

Exploitation

An attacker must have valid low-privileged credentials and access to the PowerStore Manager web console. The attacker inserts crafted script payloads into unsuspecting input fields or other user-controllable data that are not properly sanitized by the application. When a victim (potentially an administrator) views the affected page, the injected script executes within their browser session [1].

Impact

Successful exploitation leads to arbitrary JavaScript execution in the victim's browser context. Depending on the victim's privileges (e.g. an admin with high permissions), the attacker could steal session cookies, perform actions as the victim, access sensitive configuration data, or deface the management interface [1].

Mitigation

Dell has released PowerStoreT OS version 4.0.0.0-2284811 which addresses this vulnerability [1]. Users should upgrade to this version or later. There is no known workaround; upgrading is the recommended course of action [1].

AI Insight generated on Jun 16, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.

References

1

News mentions

0

No linked articles in our index yet.