Cisco Prime Collaboration Deployment vulnerability: Un authenticated remote attacker can conduct cross-site scripting attack
CVE-2023-20060
Key Information:
- Vendor
- Cisco
- Vendor
- CVE Published:
- 15 November 2024
Summary
A vulnerability in the web-based management interface of Cisco Prime Collaboration Deployment enables an unauthenticated remote attacker to perform a cross-site scripting attack. This flaw arises due to the interface's failure to adequately validate user inputs. An attacker can exploit this by tricking a user into clicking a specially crafted link, which may lead to the execution of arbitrary script code within the context of the affected interface. Consequently, sensitive browser-based information could be accessed. Cisco is expected to provide software updates to mitigate this vulnerability, and no workarounds are currently available.
Affected Version(s)
Cisco Prime Collaboration Deployment 11.5(1)
Cisco Prime Collaboration Deployment 11.0(1a)
Cisco Prime Collaboration Deployment 11.5(1)SU1
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved