Cross-Site Scripting Vulnerability in Cisco Integrated Management Controller Interface
CVE-2023-20228
6.1MEDIUM
Key Information:
- Vendor
Cisco
- Status
- Vendor
- CVE Published:
- 16 August 2023
What is CVE-2023-20228?
A vulnerability has been identified in the web-based management interface of Cisco Integrated Management Controller (IMC). This issue stems from inadequate validation of user input, which could enable an unauthorized remote attacker to execute cross-site scripting (XSS) attacks against users interacting with the interface. By enticing a user to click on a specially crafted link, the attacker may run arbitrary script code within the user's browser or access sensitive data managed through the browser. This highlights the importance of input validation and safe browsing practices.
Affected Version(s)
Cisco Identity Services Engine Software
Cisco Unified Computing System (Standalone) 3.1(1d)
Cisco Unified Computing System (Standalone) 3.1(2b)