PT-2025-18079 · Dell · Dell Powerprotect Data Manager Reporting

Published

2025-04-24

·

Updated

2025-05-13

·

CVE-2025-23376

CVSS v2.0

4.6

Medium

VectorAV:L/AC:L/Au:S/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Dell PowerProtect Data Manager Reporting versions 19.16 through 19.18
Description The issue is related to an Improper Neutralization of Special Elements Used in a Template Engine. A high privileged attacker with local access could potentially exploit this, leading to information disclosure.
Recommendations For versions 19.16 through 19.18, update to a version that contains a fix for this issue, as using a vulnerable version could lead to information disclosure. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Code Injection

Weakness Enumeration

Related Identifiers

BDU:2025-05912
CVE-2025-23376

Affected Products

Dell Powerprotect Data Manager Reporting