Home

Description

Dell PowerProtect Data Manager Reporting, version(s) 19.16, 19.17, 19.18, contain(s) an Improper Neutralization of Special Elements Used in a Template Engine vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to information disclosure.

PUBLISHED Reserved 2025-01-15 | Published 2025-04-28 | Updated 2025-04-28 | Assigner dell




LOW: 2.3CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N

Problem types

CWE-1336: Improper Neutralization of Special Elements Used in a Template Engine

Product status

Default status
unaffected

19.15.0 (semver)
affected

References

www.dell.com/...ta-manager-multiple-security-vulnerabilities vendor-advisory

cve.org (CVE-2025-23376)

nvd.nist.gov (CVE-2025-23376)

Download JSON