CyberRota Analysis
AI-GeneratedDell PowerProtect Data Domain products, specifically versions 7.7.1.0 through 8.7 and various LTS releases, are vulnerable to a stored cross-site scripting flaw that allows unauthenticated remote attackers to exploit the system. Successful exploitation could result in information disclosure, session theft, or client-side request forgery. Organizations using these versions should prioritize remediation to mitigate the risk of potential attacks.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain a stored cross-site scripting vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability. Exploitation may lead to information disclosure, session theft, or client-side request forgery.
Related CVEs
Other vulnerabilities affecting the same vendor(s)