CVE-2017-6702: XSS
Published Jul 4, 2017
·Updated
A vulnerability in the web framework of Cisco SocialMiner could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web interface of an affected system. More Information: CSCve15285. Known Affected Releases: 11.5(1).
Affected Software
1 affected component
Cisco SocialMiner=11.5\(1\)
Event History
Jul 4, 2017
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2017-6702?
CVE-2017-6702 is rated as a critical severity vulnerability due to its potential to allow XSS attacks.
2
How do I fix CVE-2017-6702?
To fix CVE-2017-6702, update Cisco SocialMiner to a patched version available from Cisco.
3
What types of attacks can CVE-2017-6702 facilitate?
CVE-2017-6702 can facilitate cross-site scripting (XSS) attacks, impacting the user's session.
4
Who is affected by CVE-2017-6702?
CVE-2017-6702 affects users of the affected versions of Cisco SocialMiner web interface.
5
Is CVE-2017-6702 exploitable remotely?
Yes, CVE-2017-6702 can be exploited by an unauthenticated remote attacker.