Reflected Cross-Site Scripting Vulnerability in Cisco Data Center Analytics Framework
CVE-2018-0145
6.1MEDIUM
Key Information:
- Vendor
Cisco
- Vendor
- CVE Published:
- 22 February 2018
What is CVE-2018-0145?
A vulnerability exists in the web-based management interface of the Cisco Data Center Analytics Framework application, enabling an unauthenticated remote attacker to execute reflected cross-site scripting (XSS) attacks. The flaw arises from inadequate validation of user-supplied input, which allows attackers to manipulate the interface by luring users into clicking malicious links. Successful exploitation can disrupt user sessions, execute arbitrary script codes, or steal sensitive information from the user's browser, posing significant risks to data integrity and user security.
Affected Version(s)
Cisco Data Center Analytics Framework Cisco Data Center Analytics Framework