CVE-2012-1512Cross-site Scripting in Vmware Vsphere

Severity
4.3MEDIUMNVD
EPSS
0.7%
top 27.97%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 16
Latest updateMay 14

Description

Cross-site scripting (XSS) vulnerability in the internal browser in vSphere Client in VMware vSphere 4.1 before Update 2 and 5.0 before Update 1 allows remote attackers to inject arbitrary web script or HTML via a crafted log-file entry.

CVSS vector

AV:N/AC:M/C:N/I:P/A:NExploitability: 8.6 | Impact: 2.9

Affected Packages6 packages

🔴Vulnerability Details

1
GHSA
GHSA-fx5m-6p6r-8x4h: Cross-site scripting (XSS) vulnerability in the internal browser in vSphere Client in VMware vSphere 42022-05-14

📋Vendor Advisories

1
VMware
VMware vCenter Server, Orchestrator, Update Manager, vShield, vSphere Client, Workstation, Player, ESXi and ESX address several security issues2012-03-15