CVE Database
/

CVE-2018-0339

Back to search

CVE-2018-0339

Published: Jun 7, 2018

Modified: Nov 29, 2024

PUBLISHED

Description

A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based interface. The vulnerability is due to insufficient input validation of some parameters passed to the web-based management interface. An attacker could exploit this vulnerability by convincing a user of the interface to click a specific link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface or allow the attacker to access sensitive browser-based information. Cisco Bug IDs: CSCvf72309.

VendorProductVersions

n/a

Cisco Identity Services Engine unknown

affected
Cisco Identity Services Engine unknown

Weaknesses (CWE)

References

104424
vdb-entry
x_refsource_BID
1041066
vdb-entry
x_refsource_SECTRACK

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now