XSS and HTML Injection Vulnerability in Cisco Email Security Appliance
CVE-2016-1423
6.1MEDIUM
Summary
A vulnerability exists in the display of email messages within the Messages in Quarantine (MIQ) view in Cisco AsyncOS for Cisco Email Security Appliance (ESA). This flaw could potentially allow an unauthenticated remote attacker to craft a malicious link that, when clicked by a user, may lead to cross-site scripting (XSS) or HTML injection attacks. The affected version 8.0.2-069 has been identified, while fixed releases include 9.1.1-038 and 9.7.2-047, ensuring enhanced security measures against such threats.
Affected Version(s)
Cisco AsyncOS 8.0.2-069 Cisco AsyncOS 8.0.2-069
References
CVSS V3.1
Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved