Cross-Site Scripting Vulnerability in Cisco Secure Access Control System
CVE-2013-6974

Currently unrated

Key Information:

Vendor
Cisco
Vendor
CVE Published:
10 January 2014

Summary

A cross-site scripting (XSS) vulnerability exists in the web interface of the Cisco Secure Access Control System (ACS), enabling remote attackers to inject arbitrary web scripts or HTML through an unspecified parameter. This flaw can potentially compromise user data, execute unauthorized actions in a user's context, and lead to exploitation of the application by delivering malicious payloads.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.