CVE-2017-6755: XSS
A vulnerability in the web portal of the Cisco Prime Collaboration Provisioning (PCP) Tool could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web interface of an affected system. More Information: CSCvc90312. Known Affected Releases: 12.1.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-6755?
CVE-2017-6755 has a high severity rating as it allows unauthenticated remote attackers to perform cross-site scripting (XSS) attacks.
How do I fix CVE-2017-6755?
To mitigate CVE-2017-6755, you should apply the latest security patches provided by Cisco for the affected versions of the Prime Collaboration Provisioning Tool.
What systems are affected by CVE-2017-6755?
CVE-2017-6755 affects Cisco Prime Collaboration Provisioning version 12.1.
What can an attacker do with CVE-2017-6755?
An attacker exploiting CVE-2017-6755 can execute arbitrary JavaScript code in the context of the user’s session, potentially compromising sensitive information.
Is there a workaround for CVE-2017-6755?
Currently, the recommended approach for CVE-2017-6755 is to upgrade to the patched software version, as specific workarounds are not provided.