Cross-site scripting in Oxygen XML WebHelp - CVE-2021-46827
Published: September 2, 2022
Vulnerability details
The disclosed vulnerability allows a remote attacker to perform cross-site scripting (XSS) attacks.
The vulnerability exists due to insufficient sanitization of user-supplied data in search terms proposals in online documentation generated with Oxygen XML WebHelp. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in user's browser in context of vulnerable website.
Successful exploitation of this vulnerability may allow a remote attacker to steal potentially sensitive information, change appearance of the web page, perform phishing and drive-by-download attacks.
Affected software
PowerStore T
Avamar Virtual Edition
Dell OpenManage Enterprise Update Manager
EMC Avamar
Dell OpenManage Enterprise Power Manager Plugin
Dell EMC OpenManage Server Administrator
EMC NetWorker Server
Dell EMC AppSync
Dell EMC Unity VSA Operating Environment (OE)
Dell EMC Unity XT Operating Environment (OE)
Dell EMC Unity Operating Environment (OE)
How to mitigate CVE-2021-46827
Dell OpenManage Enterprise Update Manager - update to 1.3
Dell OpenManage Enterprise Power Manager Plugin - update to 3.0
PowerStore T - update to 3.5.0.1-2083289
Dell EMC AppSync - update to 4.5.0.0
Dell EMC Unity VSA Operating Environment (OE) - update to 5.2.2.0.5.004
Dell EMC Unity XT Operating Environment (OE) - update to 5.2.2.0.5.004
Dell EMC Unity Operating Environment (OE) - update to 5.2.2.0.5.004
Dell EMC OpenManage Server Administrator - update to 10.3.0
EMC NetWorker Server - update to 19.7.0.2
EMC Avamar - update to 19.8
Avamar Virtual Edition - update to 19.8
External References
Related Security Bulletins
- XSS in Oxygen XML WebHelp
- XSS in Dell AppSync
- XSS in Dell OpenManage Enterprise Power Manager Plugin
- XSS in Dell OpenManage Server Administrator
- XSS in Dell OpenManage Enterprise Update Manager
- Cross-site scripting in Dell NetWorker
- Cross-site scripting in Dell Avamar Server and Avamar Virtual Edition
- Multiple vulnerabilities in Dell Unity, Dell UnityVSA, and Dell Unity XT
- Multiple vulnerabilities in Dell PowerStore Family