Описание
Cross-site scripting (XSS) vulnerability in Cisco Identity Services Engine (ISE) 1.2 patch 2 and earlier allows remote attackers to inject arbitrary web script or HTML via a report containing a crafted URL that is not properly handled during generation of report-output pages, aka Bug ID CSCui15064.
Ссылки
- Broken Link
- Permissions Required
- Vendor Advisory
- Vendor Advisory
- Third Party AdvisoryVDB Entry
- Broken Link
- Permissions Required
- Vendor Advisory
- Vendor Advisory
- Third Party AdvisoryVDB Entry
Уязвимые конфигурации
Конфигурация 1Версия до 1.2 (включая)
cpe:2.3:a:cisco:identity_services_engine_software:*:*:*:*:*:*:*:*
EPSS
Процентиль: 72%
0.00707
Низкий
4.3 Medium
CVSS2
Дефекты
CWE-79
Связанные уязвимости
github
больше 3 лет назад
Cross-site scripting (XSS) vulnerability in Cisco Identity Services Engine (ISE) 1.2 patch 2 and earlier allows remote attackers to inject arbitrary web script or HTML via a report containing a crafted URL that is not properly handled during generation of report-output pages, aka Bug ID CSCui15064.
EPSS
Процентиль: 72%
0.00707
Низкий
4.3 Medium
CVSS2
Дефекты
CWE-79