216.73.216.6

CVE-2025-23377

· Published 28/04/2025 15:15 · Modified 28/04/2025 15:15

Labels: CVE-2025-23377 2025-04-28CVE-2025-23377CWE-116[email protected]

Essential information

Published
28/04/2025 15:15
Modified
28/04/2025 15:15
Author
Creator
CVSS
4.2 MEDIUM (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:N/A:N

CVSS metrics

Description

Dell PowerProtect Data Manager Reporting, version(s) 19.17, 19.18 contain(s) an Improper Encoding or Escaping of Output vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability to inject arbitrary web script or html in reporting outputs.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
dell / powerprotect data manager cpe:2.3:a:dell:powerprotect_data_manager:19.17:*:*:*:*:*:*:*
dell / powerprotect data manager cpe:2.3:a:dell:powerprotect_data_manager:19.18:*:*:*:*:*:*:*

References