4.3
CVSSv2

CVE-2015-6356

Published: 04/11/2015 Updated: 07/12/2016
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in the WeChat page in Cisco Social Miner 10.0(1) allows remote malicious users to inject arbitrary web script or HTML via unspecified vectors, aka Bug ID CSCuw60212.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco socialminer 10.0\\(1\\)

Vendor Advisories

A vulnerability in the WeChat page of Cisco Social Miner could allow an unauthenticated, remote attacker to send a malicious script to an unsuspecting user The vulnerability is due to insufficient input validation An attacker could exploit this vulnerability by convincing the user of the affected device to follow a malicious link or visit an at ...