CVE-2025-36577
Description
Dell Wyse Management Suite, versions prior to WMS 5.2, contain an Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Script injection.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
A high-privileged XSS vulnerability in Dell Wyse Management Suite before 5.2 allows script injection via improper input neutralization.
Vulnerability
Dell Wyse Management Suite (WMS) versions prior to 5.2 contain an Improper Neutralization of Input During Web Page Generation vulnerability, commonly known as Cross-site Scripting (XSS) [1]. The issue exists in the proprietary code of WMS, where user-supplied input is not properly sanitized before being reflected in web pages, enabling script injection [1].
Exploitation
An attacker with high privileges (e.g., administrator-level access) and remote network access can exploit this vulnerability by crafting a malicious input that, when processed by the vulnerable WMS component, injects client-side scripts [1]. User interaction is required for successful exploitation, as the victim must visit a crafted link or page containing the injected script [1].
Impact
Successful exploitation allows the attacker to execute arbitrary scripts in the context of an authenticated user's browser session [1]. This can lead to disclosure of sensitive information (confidentiality impact) and potential unauthorized modification of data (integrity impact) within the affected WMS environment [1]. The CVSS v3.1 base score is 6.1 (AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:N) [1].
Mitigation
The vulnerability is fixed in Dell Wyse Management Suite version 5.2 [1]. Users should upgrade to WMS 5.2 or later to mitigate the risk. No workarounds are provided in the advisory [1].
AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Range: <5.2
- Range: N/A
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- www.dell.com/support/kbdoc/en-us/000325679/dsa-2025-226mitrevendor-advisory
News mentions
0No linked articles in our index yet.