First published: Mon Apr 01 2013(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in the element-list implementation in Cisco Connected Grid Network Management System (CG-NMS) allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka Bug IDs CSCue14517, CSCue38914, CSCue38884, CSCue38882, CSCue38881, CSCue38872, CSCue38868, CSCue38866, CSCue38853, and CSCue14540.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Connected Grid Network Management System |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-1171 is classified as a medium severity vulnerability due to its potential for remote exploitation.
To mitigate CVE-2013-1171, ensure that you apply the latest patches provided by Cisco for the Connected Grid Network Management System.
CVE-2013-1171 includes multiple cross-site scripting (XSS) vulnerabilities.
CVE-2013-1171 affects users of Cisco Connected Grid Network Management System versions that include the element-list implementation.
Yes, CVE-2013-1171 can allow remote attackers to inject arbitrary web scripts, which may lead to data breaches.