Dimension Stored XSS in Scheduled Report Task
Summary #
A stored cross-site scripting (XSS) vulnerability in WatchGuard Dimension's task scheduling feature allows a low-privileged authenticated administrator to inject arbitrary HTML/JavaScript into these fields, which then executes in the browser session of any other user.
Impact: Successful exploitation allows an attacker with low-privileged access to execute arbitrary JavaScript in the browser context of other users who view the task listing page, including administrators. This can lead to theft of session cookies/tokens, performance of unauthorized actions on behalf of the victim, UI manipulation, and further persistent attacks, potentially resulting in privilege escalation and broader administrative compromise of the Dimension system.
Product status #
| Product | Affected | Not affected |
|---|---|---|
| Dimension | >= 2.0, < 2.3.1 | >= 2.3.1 |
Weakness Type and Impact #
Exploitation Status #
Solution #
References #
Credits #
- Simone Paganessi (https://www.linkedin.com/in/simonepaganessi)finder