296,138
Total vulnerabilities in the database
VMware Aria automation contains a DOM based Cross-Site Scripting (XSS) vulnerability. A malicious actor may exploit this issue to steal the access token of a logged in user of VMware Aria automation appliance by tricking the user into clicking a malicious crafted payload URL.
Software | From | Fixed in |
---|---|---|
vmware / aria_automation | 8.18.0 | 8.18.0.x |
vmware / aria_automation | 8.18.1 | 8.18.1.x |
vmware / aria_automation | 8.18.1-patch1 | 8.18.1-patch1.x |
vmware / telco_cloud_platform | 5.0 | 5.0.1.x |
vmware / cloud_foundation | 4.0 | 5.2.1.x |