First published: Tue Dec 03 2013(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in the web interface in the Assurance component in Cisco Prime Collaboration allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka Bug IDs CSCui92643, CSCui94038, and CSCui94161.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Prime Collaboration |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-6690 is classified as a high severity vulnerability due to its potential for remote code execution through cross-site scripting.
To remediate CVE-2013-6690, upgrade to the latest version of Cisco Prime Collaboration that addresses these XSS vulnerabilities.
Organizations using Cisco Prime Collaboration for managing communications are affected by CVE-2013-6690.
CVE-2013-6690 can facilitate cross-site scripting attacks, which may lead to session hijacking and data theft.
Yes, CVE-2013-6690 can be exploited remotely by attackers to inject arbitrary web scripts or HTML into the web interface.