VMware Aria Operations for Logs
cpe:2.3:a:vmware:aria_operations_for_logs:*:*:*:*:*:*:*
- ~8.0
A stored cross-site scripting vulnerability has been identified in VMware Aria Operations for Logs. This vulnerability allows a malicious actor with non-administrative privileges to inject a script that could be executed later, potentially leading to unauthorized actions being performed as an admin user.
Exploitation of this vulnerability allows for stored cross-site scripting, where injected scripts are executed in the context of the user.
Users can upgrade to VMware Aria Operations for Logs version 8.18.3 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.