Dell Update Manager Plugin, version(s) 1.5.0 through 1.6.0, contain(s) an Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information exposure.
References
Configurations
History
04 Mar 2025, 14:53
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.4 |
CPE | cpe:2.3:a:dell:update_manager_plugin:*:*:*:*:*:*:*:* | |
References | () https://www.dell.com/support/kbdoc/en-us/000281885/dsa-2025-047-security-update-for-dell-update-manager-plugin-vulnerability - Vendor Advisory | |
First Time |
Dell
Dell update Manager Plugin |
|
CWE |
07 Feb 2025, 03:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-02-07 03:15
Updated : 2025-03-04 14:53
NVD link : CVE-2025-22402
Mitre link : CVE-2025-22402
JSON object : View
Products Affected
dell
- update_manager_plugin
CWE
No CWE.