Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-gg5f-6jp8-fpqw

Опубликовано: 05 июн. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 4.8

Описание

A vulnerability in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker to conduct a stored XSS attack by exploiting an RFI vulnerability.

This vulnerability is due to insufficient validation of user-supplied input for specific HTTP requests that are sent to an affected device. An attacker could exploit this vulnerability by persuading a user to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive information on the affected device.

A vulnerability in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker to conduct a stored XSS attack by exploiting an RFI vulnerability.

This vulnerability is due to insufficient validation of user-supplied input for specific HTTP requests that are sent to an affected device. An attacker could exploit this vulnerability by persuading a user to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive information on the affected device.

EPSS

Процентиль: 75%
0.0086
Низкий

4.8 Medium

CVSS3

Дефекты

CWE-20
CWE-79

Связанные уязвимости

CVSS3: 4.8
nvd
больше 1 года назад

A vulnerability in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker to conduct a stored XSS attack by exploiting an RFI vulnerability. This vulnerability is due to insufficient validation of user-supplied input for specific HTTP requests that are sent to an affected device. An attacker could exploit this vulnerability by persuading a user to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive information on the affected device.

CVSS3: 4.8
fstec
больше 1 года назад

Уязвимость веб-интерфейса управления программного средства автоматизации работы операторов Cisco Finesse, позволяющая нарушителю проводить межсайтовые сценарные атаки

EPSS

Процентиль: 75%
0.0086
Низкий

4.8 Medium

CVSS3

Дефекты

CWE-20
CWE-79