cisco-sa-20190123-miner-chat-xss: Cisco SocialMiner Chat Feed Cross-Site Scripting Vulnerabilities
Multiple vulnerabilities in the chat feed feature of Cisco SocialMiner could allow an unauthenticated, remote attacker to perform cross-site scripting (XSS) attacks against a user of the web-based user interface of an affected system. These vulnerabilities are due to insufficient sanitization of user-supplied input delivered to the chat feed as part of an HTTP request. An attacker could exploit these vulnerabilities by persuading a user to follow a link to attacker-controlled content. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information. There are no workarounds that address these vulnerabilities. This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190123-miner-chat-xss
Credit
Affected Software
Event History
Frequently Asked Questions
What is the severity of cisco-sa-20190123-miner-chat-xss?
The severity of cisco-sa-20190123-miner-chat-xss is classified as high due to its potential for facilitating cross-site scripting attacks.
How do I fix cisco-sa-20190123-miner-chat-xss?
To fix cisco-sa-20190123-miner-chat-xss, it is recommended to apply the latest patches or updates provided by Cisco for the affected SocialMiner software.
What systems are affected by cisco-sa-20190123-miner-chat-xss?
cisco-sa-20190123-miner-chat-xss affects installations of Cisco SocialMiner that use the chat feed feature.
Can cisco-sa-20190123-miner-chat-xss be exploited remotely?
Yes, cisco-sa-20190123-miner-chat-xss can be exploited by unauthenticated remote attackers via the web-based user interface.
What impact does cisco-sa-20190123-miner-chat-xss have on users?
The impact of cisco-sa-20190123-miner-chat-xss includes the potential to execute arbitrary scripts in the context of a user's browser, compromising their session or data.