First published: Mon Sep 30 2013(Updated: )
Cross-site scripting (XSS) vulnerability in an administration page in Cisco Identity Services Engine (ISE) allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka Bug ID CSCui30275.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Identity Services Engine |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-5505 has been assigned a medium severity rating due to its potential for exploitation via cross-site scripting.
To fix CVE-2013-5505, upgrade to the latest version of Cisco Identity Services Engine Software that addresses this vulnerability.
The impact of CVE-2013-5505 allows remote attackers to inject arbitrary web scripts or HTML, potentially compromising user data.
CVE-2013-5505 affects Cisco Identity Services Engine Software.
Currently, there are no known workarounds for CVE-2013-5505; the recommended solution is to apply the appropriate software update.