First published: Fri Jan 09 2015(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in the web framework in Cisco Secure Access Control System (ACS) allow remote attackers to inject arbitrary web script or HTML via unspecified parameters, aka Bug ID CSCuq79019.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Secure Access Control System |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-8028 is classified as a high-severity vulnerability due to its potential for exploitation via cross-site scripting.
To fix CVE-2014-8028, apply the latest security patches provided by Cisco for the Secure Access Control System.
CVE-2014-8028 can facilitate cross-site scripting (XSS) attacks, allowing attackers to inject arbitrary web scripts or HTML.
CVE-2014-8028 affects Cisco Secure Access Control System versions that have not been patched for this vulnerability.
Yes, CVE-2014-8028 can be exploited remotely by attackers to execute malicious scripts in the context of a user's browser.