Cross-Site Scripting Vulnerability in Cisco SocialMiner Web Framework
CVE-2017-6702
6.1MEDIUM
Summary
A vulnerability present in the web framework of Cisco SocialMiner allows an unauthenticated, remote attacker to execute a cross-site scripting (XSS) attack. This security flaw impacts users of the affected system's web interface, potentially leading to unauthorized actions being carried out on behalf of legitimate users, as well as exposing sensitive information. Organizations utilizing Cisco SocialMiner should take immediate measures to mitigate the risks posed by this vulnerability.
Affected Version(s)
Cisco SocialMiner Cisco SocialMiner
References
CVSS V3.1
Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved