Cross-Site Scripting Issue in Cisco Firepower Management Interface
CVE-2015-6372
Currently unrated
Key Information:
- Vendor
- Cisco
- Vendor
- CVE Published:
- 18 November 2015
Summary
The vulnerability in the web-based management interface of Cisco Firepower Extensible Operating System allows remote attackers to exploit insufficient validation of user-supplied input. By injecting arbitrary web script or HTML through a crafted value, attackers may execute malicious scripts in the context of a user's session. This could lead to unauthorized actions on behalf of users, potentially compromising sensitive information and network integrity.
References
Timeline
Vulnerability published
Vulnerability Reserved