Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7423-xf8w-j7hg

Опубликовано: 24 сент. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 6.1

Описание

A vulnerability in the web UI of Cisco IOS XE Software could allow an unauthenticated, remote attacker to conduct a reflected cross-site scripting attack (XSS) on an affected device.

This vulnerability is due to improper sanitization of user-supplied input. An attacker could exploit this vulnerability by persuading a user to click a malicious link. A successful exploit could allow the attacker to execute a reflected XSS attack and steal user cookies from the affected device.

A vulnerability in the web UI of Cisco IOS XE Software could allow an unauthenticated, remote attacker to conduct a reflected cross-site scripting attack (XSS) on an affected device.

This vulnerability is due to improper sanitization of user-supplied input. An attacker could exploit this vulnerability by persuading a user to click a malicious link. A successful exploit could allow the attacker to execute a reflected XSS attack and steal user cookies from the affected device.

EPSS

Процентиль: 21%
0.00068
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-692

Связанные уязвимости

CVSS3: 6.1
nvd
5 месяцев назад

A vulnerability in the Web Authentication feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to conduct a reflected cross-site scripting attack (XSS) on an affected device. This vulnerability is due to improper sanitization of user-supplied input. An attacker could exploit this vulnerability by persuading a user to click a malicious link. A successful exploit could allow the attacker to execute a reflected XSS attack and steal user cookies from the affected device.

CVSS3: 6.1
fstec
5 месяцев назад

Уязвимость веб-интерфейса операционных систем Cisco IOS XE, позволяющая нарушителю проводить межсайтовые сценарные атаки (XSS)

EPSS

Процентиль: 21%
0.00068
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-692