XSS and HTML Injection Vulnerability in Cisco Email Security Appliance
CVE-2016-1423
6.1MEDIUM
What is CVE-2016-1423?
A vulnerability exists in the display of email messages within the Messages in Quarantine (MIQ) view in Cisco AsyncOS for Cisco Email Security Appliance (ESA). This flaw could potentially allow an unauthenticated remote attacker to craft a malicious link that, when clicked by a user, may lead to cross-site scripting (XSS) or HTML injection attacks. The affected version 8.0.2-069 has been identified, while fixed releases include 9.1.1-038 and 9.7.2-047, ensuring enhanced security measures against such threats.
Affected Version(s)
Cisco AsyncOS 8.0.2-069 Cisco AsyncOS 8.0.2-069