First published: Tue Feb 09 2016(Updated: )
Cross-site scripting (XSS) vulnerability in Cisco Application Policy Infrastructure Controller Enterprise Module (APIC-EM) 1.1 allows remote attackers to inject arbitrary web script or HTML via crafted markup data, aka Bug ID CSCux15489.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Application Policy Infrastructure Controller (APIC) | =1.1_base |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-1318 has a medium severity rating due to its ability to allow remote attackers to execute arbitrary web scripts.
To mitigate CVE-2016-1318, users should update to the latest version of Cisco Application Policy Infrastructure Controller Enterprise Module.
CVE-2016-1318 specifically affects Cisco Application Policy Infrastructure Controller Enterprise Module version 1.1.
CVE-2016-1318 is classified as a cross-site scripting (XSS) vulnerability.
Yes, CVE-2016-1318 can be exploited by remote attackers through crafted markup data.