Cisco TelePresence Management Suite Cross-Site Scripting Vulnerability
false
Cisco TelePresence Management Suite Cross-Site Scripting Vulnerability
Cisco TelePresence Management Suite Cross-Site Scripting Vulnerability
Overview
Please be advised that Cisco announced the following medium impact security vulnerability.
A vulnerability in the web-based management interface of Cisco TelePresence Management Suite (TMS) could allow a low-privileged, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface.
This vulnerability is due to insufficient input validation by the web-based management interface. An attacker could exploit this vulnerability by inserting malicious data in a specific data field in the interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information.
There are no workarounds that address this vulnerability.
Full description of the vulnerability is available on the following link:
At the time of publication, this vulnerability affected Cisco TMS Release 15.13.6.
Fixed Software
Cisco has not released and will not release software updates to address the vulnerability that is described in this advisory. Cisco TMS has entered the end-of-life process. Customers are advised to refer to the end-of-life notices for the product