Cisco Meeting Server Persistent Cross-Site Scripting Vulnerability
The vulnerability is due to improper input validation of certain parameters that are passed to an affected device via an HTTP request. An attacker could exploit this vulnerability by persuading a user to follow a malicious link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected management interface or allow the attacker to access sensitive browser-based information.
Additional information about XSS attacks and potential mitigations can be found in the following resources:
- OWASP Attack Reference: Cross-site Scripting (XSS)
- Cisco Applied Mitigation Bulletin: Understanding Cross-Site Scripting (XSS) Threat Vectors
This advisory is available at the following link: http://ift.tt/29Tl3QJ
The vulnerability is due to improper input validation of certain parameters that are passed to an affected device via an HTTP request. An attacker could exploit this vulnerability by persuading a user to follow a malicious link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected management interface or allow the attacker to access sensitive browser-based information.
Additional information about XSS attacks and potential mitigations can be found in the following resources:
- OWASP Attack Reference: Cross-site Scripting (XSS)
- Cisco Applied Mitigation Bulletin: Understanding Cross-Site Scripting (XSS) Threat Vectors
This advisory is available at the following link: http://ift.tt/29Tl3QJ
Security Impact Rating: Medium
CVE: CVE-2016-1451
from Cisco Security Advisory http://ift.tt/29Tl3QJ