First published: Mon Jan 20 2014(Updated: )
Cross-site scripting (XSS) vulnerability in the portal in Cisco Secure Access Control System (ACS) allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka Bug ID CSCue65949.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Secure Access Control System |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-0668 is classified as a medium-severity vulnerability.
To fix CVE-2014-0668, upgrade to the latest version of Cisco Secure Access Control System as recommended in the security advisory.
CVE-2014-0668 is a cross-site scripting (XSS) vulnerability.
CVE-2014-0668 affects users of the Cisco Secure Access Control System.
Attackers exploiting CVE-2014-0668 can inject arbitrary web scripts or HTML into the affected system.