CVE-2023-20119: XSS
A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email and Web Manager, formerly known as Content Security Management Appliance (SMA) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability is due to insufficient user input validation. An attacker could exploit this vulnerability by persuading a user of an affected interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-20119?
CVE-2023-20119 is a vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email and Web Manager, which could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack.
Which software versions are affected by CVE-2023-20119?
The affected software versions are Cisco Secure Email and Web Manager 14.0.0-418, 14.0.1-033, 14.0.1-053, 15.0.0-050, and 15.0.0-256.
What is the severity of CVE-2023-20119?
The severity of CVE-2023-20119 is medium with a CVSS score of 6.1.
How can an attacker exploit CVE-2023-20119?
An unauthenticated, remote attacker can exploit CVE-2023-20119 by conducting a cross-site scripting (XSS) attack against a user of the affected software.
Where can I find more information about CVE-2023-20119?
You can find more information about CVE-2023-20119 in the Cisco Security Advisory at https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-sma-wsa-xss-cP9DuEmq.