Cross-Site Scripting Vulnerability in Cisco Small Business Phones
CVE-2014-3313
Currently unrated
Key Information:
- Vendor
Cisco
- Status
- Vendor
- CVE Published:
- 9 July 2014
What is CVE-2014-3313?
A cross-site scripting (XSS) vulnerability exists in the web user interface of Cisco Small Business SPA300 and SPA500 series phones. This vulnerability enables remote attackers to inject arbitrary script or HTML content into affected devices through a specially crafted URL. If exploited, this flaw can lead to unauthorized actions performed on behalf of users accessing the UI of these phones.