CVE-2021-34760: Cisco TelePresence Management Suite Stored Cross-Site Scripting Vulnerability
A vulnerability in the web-based management interface of Cisco TelePresence Management Suite (TMS) Software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability is due to insufficient input validation by the web-based management interface. An attacker could exploit this vulnerability by inserting malicious data in a specific data field in the interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-34760?
CVE-2021-34760 is a vulnerability in the web-based management interface of Cisco TelePresence Management Suite (TMS) Software that could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface.
How severe is CVE-2021-34760?
The severity of CVE-2021-34760 is medium, with a CVSS score of 4.8.
Which software is affected by CVE-2021-34760?
Cisco TelePresence Management Suite (TMS) Software versions up to and including 15.13.2 are affected by CVE-2021-34760.
What is the Common Weakness Enumeration (CWE) ID for CVE-2021-34760?
CVE-2021-34760 is associated with CWE-79 and CWE-20.
How can I fix CVE-2021-34760?
To fix CVE-2021-34760, it is recommended to upgrade to a version of Cisco TelePresence Management Suite (TMS) Software that is not affected by the vulnerability.