CVE-2015-4268
published 2015-07-14CVE-2015-4268: Multiple cross-site scripting (XSS) vulnerabilities in the Infra Admin UI in Cisco Identity Services Engine (ISE) 1.2(1.198) and 1.3(0.876) allow remote…
PriorityP420medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
1.55%
72.1th percentile
Multiple cross-site scripting (XSS) vulnerabilities in the Infra Admin UI in Cisco Identity Services Engine (ISE) 1.2(1.198) and 1.3(0.876) allow remote attackers to inject arbitrary web script or HTML via unspecified parameters in a (1) GET or (2) POST request, aka Bug ID CSCus16052.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | identity_services_engine_software | — | — |
| cisco | identity_services_engine_software | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
vendor_cisco4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-p33f-5f4f-x3rj: Multiple cross-site scripting (XSS) vulnerabilities in the Infra Admin UI in Cisco Identity Services Engine (ISE) 1
ghsa_unreviewed·2022-05-17
CVE-2015-4268 [MEDIUM] CWE-79 GHSA-p33f-5f4f-x3rj: Multiple cross-site scripting (XSS) vulnerabilities in the Infra Admin UI in Cisco Identity Services Engine (ISE) 1
Multiple cross-site scripting (XSS) vulnerabilities in the Infra Admin UI in Cisco Identity Services Engine (ISE) 1.2(1.198) and 1.3(0.876) allow remote attackers to inject arbitrary web script or HTML via unspecified parameters in a (1) GET or (2) POST request, aka Bug ID CSCus16052.
Cisco
Cisco Identity Services Engine Cross-Site Scripting Vulnerability
vendor_cisco·2015-07-13·CVSS 4.3
CVE-2015-4268 [MEDIUM] CWE-79 Cisco Identity Services Engine Cross-Site Scripting Vulnerability
Cisco Identity Services Engine Cross-Site Scripting Vulnerability
A vulnerability in the Cisco Identity Services Engine (ISE) Infra Admin UI could allow an unauthenticated, remote attacker to perform a cross-site scripting (XSS) attack.
The vulnerability is due to insufficient input validation of some parameters passed via HTTP GET or POST methods. An attacker could exploit this vulnerability by intercepting the user packets and injecting malicious code. An exploit could allow the attacker to execute arbitrary script code in the context of the affected site or allow the attacker to access sensitive browser-based information.
Cisco has confirmed the vulnerability and released software updates.
To exploit the vulnerability, the attacker may provide a link that directs a user to a malici
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2015-07-14
Published