CVE-2019-3708
Last modified
CVE-2019-3708 is a vulnerability of currently unknown severity. IsilonSD Management Server 1.1.0 contains a cross-site scripting vulnerability while uploading an OVA file. A remote attacker can trick an admin user to potentially exploit this vulnerability to execute malicious HTML or JavaScript code in the context of the admin user.. EPSS estimates a 2.25% chance of exploitation in the next 30 days.
Description
IsilonSD Management Server 1.1.0 contains a cross-site scripting vulnerability while uploading an OVA file. A remote attacker can trick an admin user to potentially exploit this vulnerability to execute malicious HTML or JavaScript code in the context of the admin user.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Dell | Emc Isilonsd Management Server | 1.1.0 |
References
- https://seclists.org/fulldisclosure/2019/Apr/16Mailing List, Third Party Advisory
- https://seclists.org/fulldisclosure/2019/Apr/16Mailing List, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-3708?
How severe is CVE-2019-3708?
How do I fix CVE-2019-3708?
Are you affected by CVE-2019-3708?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
