Lucene search

K
ciscoCiscoCISCO-SA-20151103-CSM
HistoryNov 03, 2015 - 5:53 p.m.

Cisco SocialMiner WeChat Page Cross-Site Scripting Vulnerability

2015-11-0317:53:00
tools.cisco.com
21

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

EPSS

0.001

Percentile

49.1%

A vulnerability in the WeChat page of Cisco Social Miner could allow an unauthenticated, remote attacker to send a malicious script to an unsuspecting user.

The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by convincing the user of the affected device to follow a malicious link or visit an attacker-controlled website. An exploit could allow the attacker to submit arbitrary requests to the affected device via the affected web browser with the privileges of the user.

Cisco has not released software updates that address this vulnerability. Workarounds that mitigate this vulnerability are not available.

This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20151103-csm[“https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20151103-csm”]

Affected configurations

Vulners
Node
ciscosocialminerMatchany
OR
ciscosocialminerMatchany
VendorProductVersionCPE
ciscosocialmineranycpe:2.3:a:cisco:socialminer:any:*:*:*:*:*:*:*

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

EPSS

0.001

Percentile

49.1%

Related for CISCO-SA-20151103-CSM