Cisco Prime Collaboration Deployment vulnerability: Un authenticated remote attacker can conduct cross-site scripting attack
CVE-2023-20060

6.1MEDIUM

Key Information:

Vendor
Cisco
Vendor
CVE Published:
15 November 2024

Summary

A vulnerability in the web-based management interface of Cisco Prime Collaboration Deployment enables an unauthenticated remote attacker to perform a cross-site scripting attack. This flaw arises due to the interface's failure to adequately validate user inputs. An attacker can exploit this by tricking a user into clicking a specially crafted link, which may lead to the execution of arbitrary script code within the context of the affected interface. Consequently, sensitive browser-based information could be accessed. Cisco is expected to provide software updates to mitigate this vulnerability, and no workarounds are currently available.

Affected Version(s)

Cisco Prime Collaboration Deployment 11.5(1)

Cisco Prime Collaboration Deployment 11.0(1a)

Cisco Prime Collaboration Deployment 11.5(1)SU1

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.