Reflected Cross-Site Scripting Vulnerability in Cisco Data Center Analytics Framework
CVE-2018-0145

6.1MEDIUM

Key Information:

Vendor
Cisco
Vendor
CVE Published:
22 February 2018

Summary

A vulnerability exists in the web-based management interface of the Cisco Data Center Analytics Framework application, enabling an unauthenticated remote attacker to execute reflected cross-site scripting (XSS) attacks. The flaw arises from inadequate validation of user-supplied input, which allows attackers to manipulate the interface by luring users into clicking malicious links. Successful exploitation can disrupt user sessions, execute arbitrary script codes, or steal sensitive information from the user's browser, posing significant risks to data integrity and user security.

Affected Version(s)

Cisco Data Center Analytics Framework Cisco Data Center Analytics Framework

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.