Cisco Secure Access Control Server Multiple Cross-Site Scripting Vulnerabilities

Related Vulnerabilities: CVE-2014-8028  

A vulnerability in the web framework of Cisco Secure Access Control Server (ACS) could allow an unauthenticated, remote attacker to perform multiple cross-site scripting (XSS) attacks against a user of the web interface on the affected system. The vulnerability is due to insufficient input validation of several parameters passed to the web server. An attacker could exploit this vulnerability by persuading a user to access a malicious link. An exploit could allow the attacker to run arbitrary scripts in the context of the user's browser. Cisco has confirmed the vulnerabilities in a security notice and has released software updates. To exploit the vulnerability, the attacker may provide a link that directs a user to a malicious site and use misleading language or instructions to persuade the user to follow the provided link. Cisco indicates through the CVSS score that functional exploit code exists; however, the code is not known to be publicly available.