Lucene search

K
prionPRIOn knowledge basePRION:CVE-2022-20967
HistoryJan 20, 2023 - 7:15 a.m.

Cross site scripting

2023-01-2007:15:00
PRIOn knowledge base
www.prio-n.com
6
cross site scripting
cisco identity services engine
web-based management interface
authentication
remote attacker
improper validation
html
script code
software updates
nvd

0.001 Low

EPSS

Percentile

26.0%

A vulnerability in the web-based management interface of Cisco Identity Services Engine could allow an authenticated, remote attacker to conduct cross-site scripting attacks against other users of the application web-based management interface.

This vulnerability is due to improper validation of input to an application feature before storage within the web-based management interface. An attacker could exploit this vulnerability by creating entries within the application interface that contain malicious HTML or script code. A successful exploit could allow the attacker to store malicious HTML or script code within the application interface for use in further cross-site scripting attacks.

Cisco has not yet released software updates that address this vulnerability.

0.001 Low

EPSS

Percentile

26.0%

Related for PRION:CVE-2022-20967