CVE-2017-12269

MEDIUM

Cisco Spark Messaging Software - XSS

Title source: llm
STIX 2.1

Description

A vulnerability in the web UI of Cisco Spark Messaging Software could allow an authenticated, remote attacker to perform a stored cross-site scripting (XSS) attack. The vulnerability is due to insufficient input validation by the web UI of the affected software. An attacker could exploit this vulnerability by injecting XSS content into the web UI of the affected software. A successful exploit could allow the attacker to force a user to execute code of the attacker's choosing or allow the attacker to retrieve sensitive information from the user. Cisco Bug IDs: CSCvf70587, CSCvf70592.

References (2)

Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/101150

Scores

CVSS v3 5.4
EPSS 0.0093
EPSS Percentile 56.7%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (2)
cisco/spark
n/a/Cisco Spark Messaging Cisco Spark Messaging
Published Oct 05, 2017
Tracked Since Feb 18, 2026