CVE-2019-15278: Cisco Finesse Cross-Site Scripting Vulnerability
A vulnerability in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker to bypass authorization and access sensitive information related to the device. The vulnerability exists because the software fails to sanitize URLs before it handles requests. An attacker could exploit this vulnerability by submitting a crafted URL. A successful exploit could allow the attacker to gain unauthorized access to sensitive information.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-15278?
CVE-2019-15278 is a vulnerability in the web-based management interface of Cisco Finesse.
How does CVE-2019-15278 affect Cisco Finesse?
CVE-2019-15278 allows an unauthenticated, remote attacker to bypass authorization and access sensitive information.
What is the severity of CVE-2019-15278?
CVE-2019-15278 has a severity rating of medium.
How can I fix CVE-2019-15278?
To fix CVE-2019-15278, apply the necessary updates or patches provided by Cisco.
Where can I find more information about CVE-2019-15278?
You can find more information about CVE-2019-15278 on the Cisco Security Advisory page.