Dimension Stored XSS via Backup Historical Data Feature
Summary #
A Cross-Site Scripting (XSS) vulnerability in the WatchGuard Dimension Backup Historical Data feature allows an authenticated administrator user to execute arbitrary JavaScript in another user's browser.
Impact: An authenticated attacker with low privileges can achieve persistent stored cross-site scripting that executes in the context of other Dimension users, including administrators, when they browse the tasks listing page. This can lead to session/token theft, unauthorized actions performed on behalf of the victim, UI manipulation, and further compromise of the Dimension administrative console.
Product status #
| Product | Affected | Not affected |
|---|---|---|
| Dimension | >= 2.0, < 2.3.1 | >= 2.3.1 |
Weakness Type and Impact #
Exploitation Status #
WatchGuard is not aware of any exploitation of this vulnerability in the wild.
Solution #
Dimension 2.3.1
References #
Credits #
- Simone Paganessi (https://www.linkedin.com/in/simonepaganessi)finder