Junglewise Threat Intelligence

CVE-2024-30476: Dell PowerStore stored XSS in PowerStore Manager

CVE-2024-30476 · Severity: medium · CVSS 5.4 · Published 2026-06-16

Vendors: Dell.

Executive brief

Dell PowerStore Manager, the administrative interface for Dell's enterprise storage systems, is vulnerable to a security flaw that allows malicious scripts to be saved on the system. A low-privileged user could use this to target other administrators, potentially leading to unauthorized actions or the theft of session information when the victim views certain pages. This could compromise the integrity of the storage management console.

Technical details

A stored cross-site scripting (XSS) vulnerability exists in the Dell PowerStore Manager GUI (CWE-79). The vulnerability is caused by improper neutralization of user-supplied input during web page generation. A remote authenticated attacker with low privileges can inject malicious scripts into the application's data store. When an unsuspecting user (typically an administrator) views the affected page, the script executes within their browser context. This can lead to session hijacking, unauthorized configuration changes, or information disclosure. The vulnerability is addressed in PowerStore OS version 4.0.0.0.

Affected products

  • Dell PowerStore Manager All versions prior to 4.0.0.0

Timeline

  • 2026-06-16: disclosed
  • 2026-06-16: advisory

References