CVE-2012-1512 — Cross-site Scripting in Vmware Vsphere
Severity
4.3MEDIUMNVD
EPSS
0.7%
top 27.97%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 16
Latest updateMay 14
Description
Cross-site scripting (XSS) vulnerability in the internal browser in vSphere Client in VMware vSphere 4.1 before Update 2 and 5.0 before Update 1 allows remote attackers to inject arbitrary web script or HTML via a crafted log-file entry.
CVSS vector
AV:N/AC:M/C:N/I:P/A:NExploitability: 8.6 | Impact: 2.9
Affected Packages6 packages
🔴Vulnerability Details
1GHSA▶
GHSA-fx5m-6p6r-8x4h: Cross-site scripting (XSS) vulnerability in the internal browser in vSphere Client in VMware vSphere 4↗2022-05-14
📋Vendor Advisories
1VMware▶
VMware vCenter Server, Orchestrator, Update Manager, vShield, vSphere Client, Workstation, Player, ESXi and ESX address several security issues↗2012-03-15