CVE-2013-7025
Summary
| CVE | CVE-2013-7025 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2013-12-09 16:36:50 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | Multiple cross-site scripting (XSS) vulnerabilities in ematStaticAlertTypes.jsp in the Alert Settings section in Dell SonicWALL Global Management System (GMS), Analyzer, and UMA EM5000 7.1 SP1 before Hotfix 134235 allow remote authenticated users to inject arbitrary web script or HTML via the (1) valfield_1 or (2) value_1 parameter to createNewThreshold.jsp. |
Risk And Classification
Primary CVSS: v2.0 3.5 from [email protected]
AV:N/AC:M/Au:S/C:N/I:P/A:N
EPSS: 0.031040000 probability, percentile 0.868520000 (date 2026-04-29)
Problem Types: CWE-79 | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
SingleConfidentiality
NoneIntegrity
PartialAvailability
NoneAV:N/AC:M/Au:S/C:N/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Sonicwall | Analyzer | 7.0 | All | All | All |
| Application | Sonicwall | Analyzer | 7.1 | All | All | All |
| Application | Sonicwall | Analyzer | 7.1 | sp1 | All | All |
| Application | Sonicwall | Global Management System | 7.0 | All | All | All |
| Application | Sonicwall | Global Management System | 7.1 | All | All | All |
| Application | Sonicwall | Global Management System | 7.1 | sp1 | All | All |
| Hardware | Sonicwall | Uma E5000 | - | All | All | All |
| Operating System | Sonicwall | Uma E5000 Firmware | 7.0 | All | All | All |
| Operating System | Sonicwall | Uma E5000 Firmware | 7.1 | All | All | All |
| Operating System | Sonicwall | Uma E5000 Firmware | 7.1 | sp1 | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| 403 Forbidden | af854a3a-2127-422b-91ae-364da2661108 | www.vulnerability-lab.com | Exploit |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | VDB Entry |
| Sonicwall GMS 7.x - Filter Bypass & Persistent Vulnerability (0Day) | af854a3a-2127-422b-91ae-364da2661108 | www.exploit-db.com | Exploit, Third Party Advisory, VDB Entry |
| SonicWALL GMS/Analyzer/UMA Input Validation Flaw in 'Alert Settings' Request Permits Cross-Site Scripting Attacks - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | Third Party Advisory, VDB Entry |
| osvdb.org/100610 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | Broken Link |
| Security Advisory SA55923 - SonicWALL Multiple Products Two Script Insertion Vulnerabilities - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Third Party Advisory |
| Full Disclosure: Sonicwall GMS v7.x - Filter Bypass & Persistent Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | seclists.org | Exploit, Mailing List, Third Party Advisory |
| Page Not Found | af854a3a-2127-422b-91ae-364da2661108 | www.sonicwall.com | Vendor Advisory |
| archives.neohapsis.com/archives/bugtraq/2013-12/0022.html | af854a3a-2127-422b-91ae-364da2661108 | archives.neohapsis.com | Third Party Advisory |
| Multiple Dell SonicWALL Products Multiple HTML Injection Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Exploit, Third Party Advisory, VDB Entry |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.