CVE-2017-6611Cross-site Scripting in Cisco Prime Infrastructure

Severity
6.1MEDIUMNVD
EPSS
0.2%
top 58.61%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 20
Latest updateMay 17

Description

A vulnerability in the web framework code of Cisco Prime Infrastructure 2.2(2) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against the user of the web interface of the affected system. The vulnerability is due to insufficient input validation of some parameters passed to the web server. An attacker could exploit this vulnerability by convincing the user to access a malicious link or by intercepting the user request and injecting the malicious co

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages2 packages

CVEListV5cisco/cisco_prime_infrastructureCisco Prime Infrastructure

🔴Vulnerability Details

2
GHSA
GHSA-r7f2-xj45-f5xp: A vulnerability in the web framework code of Cisco Prime Infrastructure 22022-05-17
CVEList
CVE-2017-6611: A vulnerability in the web framework code of Cisco Prime Infrastructure 22017-04-20

📋Vendor Advisories

1
Cisco
Cisco Prime Infrastructure Web Framework Code Cross-Site Scripting Vulnerability2017-04-19
CVE-2017-6611 — Cross-site Scripting in Cisco | cvebase