CVE-2019-1882

A vulnerability in Cisco Industrial Network Director could allow an authenticated, remote attacker to conduct stored cross-site scripting (XSS) attacks. The vulnerability is due to improper validation of content submitted to the affected application. An attacker could exploit this vulnerability by sending requests containing malicious values to the affected system. A successful exploit could allow the attacker to conduct XSS attacks.
Configurations

Configuration 1 (hide)

cpe:2.3:a:cisco:industrial_network_director:1.5\(0.250\):*:*:*:*:*:*:*

History

21 Nov 2024, 04:37

Type Values Removed Values Added
References () http://www.securityfocus.com/bid/108629 - Third Party Advisory, VDB Entry () http://www.securityfocus.com/bid/108629 - Third Party Advisory, VDB Entry
References () https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190605-ind-xss - Vendor Advisory () https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190605-ind-xss - Vendor Advisory

Information

Published : 2019-06-05 17:29

Updated : 2024-11-21 04:37


NVD link : CVE-2019-1882

Mitre link : CVE-2019-1882

CVE.ORG link : CVE-2019-1882


JSON object : View

Products Affected

cisco

  • industrial_network_director
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')