Stored XSS Vulnerability in Cisco Prime Infrastructure and Evolved Programmable Network Manager
CVE-2023-20201
5.4MEDIUM
Key Information:
- Vendor
Cisco
- Vendor
- CVE Published:
- 16 August 2023
What is CVE-2023-20201?
Cisco's web-based management interfaces for Prime Infrastructure and Evolved Programmable Network Manager are exposed to multiple vulnerabilities. These issues arise from inadequate validation of user-supplied input, allowing an authenticated remote attacker to execute a stored XSS attack. An attacker may entice a valid user to access a compromised page containing malicious HTML or JavaScript. Successful exploitation could lead to arbitrary script execution within the context of the user's session, potentially exposing sensitive browser-based information.
Affected Version(s)
Cisco Evolved Programmable Network Manager (EPNM) 1.2.6
Cisco Evolved Programmable Network Manager (EPNM) 1.2.2
Cisco Evolved Programmable Network Manager (EPNM) 1.2.3