First published: Thu Jul 28 2016(Updated: )
Cross-site scripting (XSS) vulnerability in the web-based management interface in Cisco Prime Service Catalog (PSC) 11.0 allows remote attackers to inject arbitrary web script or HTML via a crafted value, aka Bug ID CSCuz63795.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Prime Service Catalog | =11.0_base |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2016-1462 is classified as medium due to its potential impact on the integrity of the web-based management interface.
To fix CVE-2016-1462, upgrade to a patched version of Cisco Prime Service Catalog that addresses this vulnerability.
CVE-2016-1462 affects Cisco Prime Service Catalog version 11.0_base.
CVE-2016-1462 is a Cross-site scripting (XSS) vulnerability allowing remote attackers to inject arbitrary web script or HTML.
Yes, CVE-2016-1462 can be exploited remotely by attackers to execute scripts in the context of the victim's web browser.