Cross-Site Scripting Vulnerability in Cisco Secure Access Control Server
CVE-2015-6346

Currently unrated

Key Information:

Vendor
Cisco
Vendor
CVE Published:
30 October 2015

Summary

A cross-site scripting vulnerability exists in Cisco Secure Access Control Server (ACS) version 5.7(0.15), which enables remote attackers to inject arbitrary web scripts or HTML by crafting a malicious URL. This can lead to various security risks as the injected code may execute in the context of the user's browser, potentially compromising sensitive information or gaining unauthorized access.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.