PT-2013-6245 · Dell · Sonicwall Global Management System+2
Benjamin Kunz Mejri
·
Published
2013-12-09
·
Updated
2018-03-12
·
CVE-2013-7025
CVSS v2.0
3.5
Low
| Vector | AV:N/AC:M/Au:S/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Dell SonicWALL Global Management System (GMS), Analyzer, and UMA EM5000 version 7.1 SP1 before Hotfix 134235
Description
The issue concerns multiple cross-site scripting (XSS) vulnerabilities in the ematStaticAlertTypes.jsp file within the Alert Settings section. These vulnerabilities allow remote authenticated users to inject arbitrary web script or HTML via specific parameters. The vulnerable parameters are
valfield 1 and value 1 in the createNewThreshold.jsp endpoint.Recommendations
For Dell SonicWALL Global Management System (GMS), Analyzer, and UMA EM5000 version 7.1 SP1 before Hotfix 134235, apply Hotfix 134235 to resolve the issue. As a temporary workaround, consider restricting access to the
createNewThreshold.jsp endpoint and avoid using the valfield 1 and value 1 parameters until the hotfix is applied.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Analyzer
Sonicwall Global Management System
Uma Em5000