Dell EMC Unity and UnityVSA contains reflected cross-site scripting vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability by tricking a victim application user to supply malicious HTML or Java Script code to Unisphere, which is then reflected back to the victim and executed by the web browser.
- https://seclists.org/fulldisclosure/2018/Sep/30
- https://github.com/ARPSyndicate/cve-scores