Cross-Site Scripting Vulnerability in Cisco BroadWorks Platforms
CVE-2023-20019

6.1MEDIUM

Key Information:

Vendor
Cisco
Vendor
CVE Published:
20 January 2023

Summary

A vulnerability exists in the web-based management interface of Cisco BroadWorks platforms that could permit an unauthenticated remote attacker to execute a cross-site scripting attack. The flaw is due to improper validation of user-supplied input, allowing attackers to craft malicious links that, when clicked by users, could lead to the execution of arbitrary script code within the context of the interface. This could potentially expose sensitive information stored in the user's browser, compromising security.

Affected Version(s)

Cisco BroadWorks 24.0 ap375672

Cisco BroadWorks 24.0 ap375655

Cisco BroadWorks 24.0 ap376979

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.