Cross-Site Scripting Vulnerability in Cisco BroadWorks Platforms
CVE-2023-20019
6.1MEDIUM
Summary
A vulnerability exists in the web-based management interface of Cisco BroadWorks platforms that could permit an unauthenticated remote attacker to execute a cross-site scripting attack. The flaw is due to improper validation of user-supplied input, allowing attackers to craft malicious links that, when clicked by users, could lead to the execution of arbitrary script code within the context of the interface. This could potentially expose sensitive information stored in the user's browser, compromising security.
Affected Version(s)
Cisco BroadWorks 24.0 ap375672
Cisco BroadWorks 24.0 ap375655
Cisco BroadWorks 24.0 ap376979
References
CVSS V3.1
Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved