Vulnslist

find the latest Cisco vulnerabilities

Cisco Emergency Responder Web Framework Cross-Site Scripting Vulnerability

cisco-sa-20151210-cer · Medium · Published · Updated

A vulnerability in the web framework of Cisco Emergency Responder Software could allow an unauthenticated, remote attacker to execute a stored cross-site scripting (XSS) attack against the user of the web interface. The vulnerability is due to  insufficient validation on the input fields of a web form. An attacker could exploit this vulnerability by entering malicious code in an affected form that is then stored in the database. Cisco has not released software updates that address this vulnerability. Workarounds that mitigate this vulnerability are not available. This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20151210-cer

Workarounds

Workarounds are not available.

CVEsCVE-2015-6400
Cisco Bug IDsCSCuv25547
CVSS ScoreBase 4.3
Base 4.3 AV:N/AC:M/Au:N/C:N/I:P/A:N/E:F/RL:U/RC:C
Product Names From Source
Cisco Emergency Responder

Related Products

Product CVE Evidence
Cisco Nexus Dashboard CVE-2015-6400 Cisco OpenVuln
Cisco Catalyst PON Series Switches CVE-2015-6400 Cisco OpenVuln
Cisco Emergency Responder CVE-2015-6400 Cisco OpenVuln