Multiple vulnerabilities in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email and Web Manager; Cisco Secure Email Gateway, formerly Cisco Email Security Appliance (ESA); and Cisco Secure Web Appliance, formerly Cisco Web Security Appliance (WSA), could allow a remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. For more information about these vulnerabilities, see the Details section of this advisory.
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:NCisco Secure Email And Web Manager
APPCisco14.0.0-41814.0.1-03314.0.1-05315.0.0-05015.0.0-256Cisco Secure Email Gateway
APPCisco14.0.0-41814.0.1-03314.0.1-05315.0.0-05015.0.0-256Cisco Web Security Appliance
APPCisco14.0.0-41814.0.1-03314.0.1-05315.0.0-05015.0.0-256
Related vulnerabilities
Cisco Secure Email Gateway — nadpisywanie dowolnych plików przez załącznik e-mail
RCE w Hyland Perceptive Filters — błąd segmentacji przy przetwarzaniu dokumentów
ClamAV: RCE przez buffer overflow w parserze partycji HFS+
Cisco ESA/SMA: pominięcie uwierzytelnienia LDAP w interfejsie webowym
A vulnerability in the web management interface of Cisco Secure Email and Web Manager, formerly Cisco Security...