Vulnerability Bulletins |
Cisco Identity Services Engine Admin Dashboard Page Cross-Site Scripting Vulnerability |
|
| Affected software | Cisco |
|
A vulnerability in the web framework code of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack.The vulnerability is due to insufficient input validation of some parameters passed to the web server. An attacker could exploit this vulnerability by convincing the user to access a malicious link or by intercepting the users request and injecting malicious code. An exploit could allow the attacker to execute arbitrary More info: http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160817-ise?vs_f=Cisco%20Security%20Advisory&vs_cat=Security%20Intelligence&vs_type=RSS&vs_p=Cisco%20Identity%20Services%20Engine%20Admin%20Dashboard%20Page%20Cross-Site%2 |
|






