VMware vCenter Server Web Client Cross-Site Scripting Vulnerability Fixed by VMSA-2016-0009
Description
(:A cross-site scripting was reported in the vSphere Web Client of VMware vCenter Server.:A remote attacker could exploit it by enticing their victim into following a specially crafted link in order to execute arbitrary JavaScript or HTML code.::This vulnerability stems from improper user-input validation.)