CVE-2021-21515

Dell EMC SourceOne, versions 7.2SP10 and prior, contain a Stored Cross-Site Scripting vulnerability. A remote low privileged attacker may potentially exploit this vulnerability, to hijack user sessions or to trick a victim application user to unknowingly send arbitrary requests to the server.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9 CRITICAL
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
dellCNA
9 CRITICAL
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 48%
VendorProductVersion
dellemc_sourceone
𝑥
< 7.2
dellemc_sourceone
7.2
dellemc_sourceone
7.2:sp1
dellemc_sourceone
7.2:sp2
dellemc_sourceone
7.2:sp3
dellemc_sourceone
7.2:sp4
dellemc_sourceone
7.2:sp5
dellemc_sourceone
7.2:sp6
dellemc_sourceone
7.2:sp7
dellemc_sourceone
7.2:sp8
dellemc_sourceone
7.2:sp9
𝑥
= Vulnerable software versions