CVE-2017-3866

A vulnerability in the web framework code of Cisco Prime Service Catalog could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against the user of the web interface of the affected system. More Information: CSCvc79842 CSCvc79846 CSCvc79855 CSCvc79873 CSCvc79882 CSCvc79891. Known Affected Releases: 11.1.2.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:cisco:prime_service_catalog:11.1_base:*:*:*:*:*:*:*
cpe:2.3:a:cisco:prime_service_catalog:11.1.2:*:*:*:*:*:*:*

Information

Published : 2017-03-17 15:59

Updated : 2017-07-11 18:29


NVD link : CVE-2017-3866

Mitre link : CVE-2017-3866


JSON object : View

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Advertisement

dedicated server usa

Products Affected

cisco

  • prime_service_catalog