Cross-Site Scripting Vulnerability in Cisco Secure Access Control Server
CVE-2015-6346

Currently unrated

Key Information:

Vendor

Cisco

Vendor
CVE Published:
30 October 2015

What is CVE-2015-6346?

A cross-site scripting vulnerability exists in Cisco Secure Access Control Server (ACS) version 5.7(0.15), which enables remote attackers to inject arbitrary web scripts or HTML by crafting a malicious URL. This can lead to various security risks as the injected code may execute in the context of the user's browser, potentially compromising sensitive information or gaining unauthorized access.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.