Cross-Site Scripting Vulnerability in Cisco Integrated Management Controller Interface
CVE-2023-20228
Key Information:
- Vendor
- Cisco
- Status
- Vendor
- CVE Published:
- 16 August 2023
Summary
A vulnerability has been identified in the web-based management interface of Cisco Integrated Management Controller (IMC). This issue stems from inadequate validation of user input, which could enable an unauthorized remote attacker to execute cross-site scripting (XSS) attacks against users interacting with the interface. By enticing a user to click on a specially crafted link, the attacker may run arbitrary script code within the user's browser or access sensitive data managed through the browser. This highlights the importance of input validation and safe browsing practices.
Affected Version(s)
Cisco Identity Services Engine Software
Cisco Unified Computing System (Standalone) 3.1(1d)
Cisco Unified Computing System (Standalone) 3.1(2b)
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved