First published: Wed Oct 16 2013(Updated: )
Cross-site scripting (XSS) vulnerability in the file-upload interface in Cisco Identity Services Engine (ISE) allows remote authenticated users to inject arbitrary web script or HTML via a crafted filename, aka Bug ID CSCui67495.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Identity Services Engine | ||
Cisco Identity Services Engine (ISE) |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-5541 has a medium severity level due to its potential for cross-site scripting (XSS) attacks.
To fix CVE-2013-5541, apply the latest security update provided by Cisco for the Identity Services Engine.
CVE-2013-5541 affects remote authenticated users of the Cisco Identity Services Engine who can upload files.
CVE-2013-5541 is a cross-site scripting (XSS) vulnerability related to the file-upload interface.
An attacker exploiting CVE-2013-5541 can inject arbitrary web scripts or HTML into the affected application.