Severity
4.3MEDIUM
EPSS
0.3%
top 47.19%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 16
Latest updateMay 17

Description

Cross-site scripting (XSS) vulnerability in View Manager Portal in VMware View before 4.6.1 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.

CVSS vector

AV:N/AC:M/C:N/I:P/A:NExploitability: 8.6 | Impact: 2.9

Affected Packages1 packages

NVDvmware/view4.6.0

🔴Vulnerability Details

2
GHSA
GHSA-j7xp-v28h-jrq2: Cross-site scripting (XSS) vulnerability in View Manager Portal in VMware View before 42022-05-17
CVEList
CVE-2012-1511: Cross-site scripting (XSS) vulnerability in View Manager Portal in VMware View before 42012-03-16

💥Exploits & PoCs

1
Exploit-DB
Linux Kernel (Debian 7/8/9/10 / Fedora 23/24/25 / CentOS 5.3/5.11/6.0/6.8/7.2.1511) - 'ldso_hwcap Stack Clash' Local Privilege Escalation2017-06-28

📋Vendor Advisories

2
CISA
Microsoft Graphics Device Interface (GDI) Privilege Escalation Vulnerability2022-03-03
CISA
Microsoft Malware Protection Engine Improper Restriction of Operations Vulnerability2022-03-03
CVE-2012-1511 (MEDIUM CVSS 4.3) | Cross-site scripting (XSS) vulnerab | cvebase.io