First published: Wed Nov 04 2015(Updated: )
Cross-site scripting (XSS) vulnerability in the WeChat page in Cisco Social Miner 10.0(1) allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka Bug ID CSCuw60212.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco SocialMiner | =10.0\(1\) |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-6356 has been classified with a medium severity rating due to its potential for cross-site scripting attacks.
To fix CVE-2015-6356, upgrade to Cisco Social Miner version 10.0(2) or later where the vulnerability is addressed.
CVE-2015-6356 is a cross-site scripting (XSS) vulnerability that allows for the injection of arbitrary web scripts or HTML.
CVE-2015-6356 affects users of Cisco Social Miner version 10.0(1).
Yes, CVE-2015-6356 can be exploited remotely by attackers to execute malicious scripts in the context of a user's session.