CVE-2019-1702
Cisco Enterprise Chat and Email Cross-Site Scripting Vulnerabilities
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Multiple vulnerabilities in the web-based management interface of Cisco Enterprise Chat and Email could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of the affected software. The vulnerabilities are due to insufficient validation of user-supplied input by the web-based management interface of the affected software. An attacker could exploit these vulnerabilities either by injecting malicious code in a chat window or by sending a crafted link to a user of the interface. In both cases, the attacker must persuade the user to click the crafted link or open the chat window that contains the attacker's code. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information. Version 11.6(1) is affected.
Múltiples vulnerabilidades en la interfaz de gestión web de Cisco Enterprise Chat and Email podría permitir a atacante remoto no autenticado realizar un ataque de Cross-Site Scripting (XSS) contra un usuario de la interfaz de gestión web del software afectado. Las vulnerabilidades se deben a la validación insuficiente de entrada de datos de parte del usuario en la interfaz de gestión web del software afectado. Un atacante podría explotar estas vulnerabilidades o bien inyectando código malicioso en una ventana de chat o bien enviando un enlace manipulado a un usuario de la interfaz. En ambos casos, el atacante deberá persuadir al usuario para que haga clic en el enlace manipulado o abra la ventana de chat que contiene el código del atacante. Su explotación con éxito podría permitir al atacante ejecutar código script arbitrario en el contexto de la interfaz o acceder a información sensible del navegador. La versión 11.6(1) se ve afectada.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2018-12-06 CVE Reserved
- 2019-03-11 CVE Published
- 2024-07-27 EPSS Updated
- 2024-09-16 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/107314 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Cisco Search vendor "Cisco" | Enterprise Chat And Email Search vendor "Cisco" for product "Enterprise Chat And Email" | 11.6\(1\) Search vendor "Cisco" for product "Enterprise Chat And Email" and version "11.6\(1\)" | - |
Affected
|