Cisco AnyConnect WebLaunch Cross-Site Scripting Vulnerability
The vulnerability is due to insufficient input validation of some parameters that are passed to the WebLaunch function of the affected software. An attacker could exploit this vulnerability by convincing a user to access a malicious link or by intercepting a user request and injecting malicious code into the request.
There are no workarounds that address this vulnerability.
This advisory is available at the following link:
http://ift.tt/2w1C738
The vulnerability is due to insufficient input validation of some parameters that are passed to the WebLaunch function of the affected software. An attacker could exploit this vulnerability by convincing a user to access a malicious link or by intercepting a user request and injecting malicious code into the request.
There are no workarounds that address this vulnerability.
This advisory is available at the following link:
http://ift.tt/2w1C738
Security Impact Rating: Medium
CVE: CVE-2017-6788
from Cisco Security Advisory http://ift.tt/2w1C738