Dell Update Manager Plugin, version(s) 1.5.0 through 1.6.0, contain(s) an Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information exposure.
References
Configurations
History
17 Jun 2026, 08:47
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-79 | |
| CPE | cpe:2.3:a:dell:update_manager_plugin:*:*:*:*:*:*:*:* | |
| First Time |
Dell
Dell update Manager Plugin |
|
| References | () https://www.dell.com/support/kbdoc/en-us/000281885/dsa-2025-047-security-update-for-dell-update-manager-plugin-vulnerability - Vendor Advisory | |
| Summary |
|
07 Feb 2025, 03:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-02-07 03:15
Updated : 2026-06-17 08:47
NVD link : CVE-2025-22402
Mitre link : CVE-2025-22402
CVE.ORG link : CVE-2025-22402
JSON object : View
Products Affected
dell
- update_manager_plugin
