Home

Description

A vulnerability in the web-based management interface of Cisco Prime Infrastructure Software could allow an unauthenticated, remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the interface on an affected device. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by persuading a user of the web-based management interface on an affected device to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or to access sensitive, browser-based information.

PUBLISHED Reserved 2022-10-27 | Published 2023-04-05 | Updated 2024-10-25 | Assigner cisco




MEDIUM: 6.1CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Problem types

CWE-79

Product status

Any version
affected

References

sec.cloudapps.cisco.com/...ry/cisco-sa-cisco-pi-xss-PU6dnfD9 (20230201 Cisco Prime Infrastructure Reflected Cross-Site Scripting Vulnerability) vendor-advisory

cve.org (CVE-2023-20068)

nvd.nist.gov (CVE-2023-20068)

Download JSON