4.9
CVSSv2

CVE-2017-6782

Published: 17/08/2017 Updated: 25/08/2017
CVSS v2 Base Score: 4.9 | Impact Score: 4.9 | Exploitability Score: 6.8
CVSS v3 Base Score: 5.4 | Impact Score: 2.7 | Exploitability Score: 2.3
VMScore: 436
Vector: AV:N/AC:M/Au:S/C:P/I:P/A:N

Vulnerability Summary

A vulnerability in the administrative web interface of Cisco Prime Infrastructure could allow an authenticated, remote malicious user to modify a page in the web interface of the affected application. The vulnerability is due to improper sanitization of parameter values by the affected application. An attacker could exploit this vulnerability by injecting malicious code into an affected parameter and persuading a user to access a web page that triggers the rendering of the injected code. Cisco Bug IDs: CSCve47074. Known Affected Releases: 3.2(0.0).

Vulnerable Product Search on Vulmon Subscribe to Product

cisco prime infrastructure 3.2\\(0.0\\)

Vendor Advisories

A vulnerability in the administrative web interface of Cisco Prime Infrastructure could allow an authenticated, remote attacker to modify a page in the web interface of the affected application The vulnerability is due to improper sanitization of parameter values by the affected application An attacker could exploit this vulnerability by injecti ...