QID 317340
Date Published: 2023-08-09
QID 317340: Cisco Secure Email and Web Manager Multiple Cross-Site Scripting (XSS) Vulnerabilities (cisco-sa-esa-sma-wsa-xss-cP9DuEmq)
Multiple vulnerabilities in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email and Web Manager could allow a remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface.
Affected Products
14.3 and prior versions of Cisco Secure Email and Web Manager
15.0 prior to Version 15.0.0-317 of Cisco Secure Email and Web Manager
QID Detection Logic (Authenticated):
The check matches Cisco Secure Email and Web Manager OS version retrieved via Unix Auth using "version" command.
Note: This QID only supports the hardware version of Cisco Secure Email and Web Manager
Successful exploitation could allow an authenticated, remote attacker to conduct an XSS attack against a user of the interface.
Customers are advised to refer to cisco-sa-esa-sma-wsa-xss-cP9DuEmq for more information.
- cisco-sa-esa-sma-wsa-xss-cP9DuEmq -
sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-sma-wsa-xss-cP9DuEmq
CVEs related to QID 317340
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| cisco-sa-esa-sma-wsa-xss-cP9DuEmq |
|