vendor:
VMware View
by:
7.5
CVSS
HIGH
Cross-Site Scripting
79
CWE
Product Name: VMware View
Affected Version From: Prior to 3.1.3
Affected Version To:
Patch Exists: YES
Related CWE:
CPE: a:vmware:view
Platforms Tested:
VMware View Cross-Site Scripting Vulnerability
The VMware View application fails to properly sanitize user-supplied data, leading to a cross-site scripting vulnerability. An attacker can exploit this vulnerability to execute arbitrary script code in the browser of a victim user, potentially allowing the attacker to steal authentication credentials and launch further attacks.
Mitigation:
Update to VMware View version 3.1.3 or later to address this vulnerability. Avoid clicking on suspicious links or visiting untrusted websites.