CVE-2024-20405
MEDIUMCisco Finesse - Stored Cross-Site Scripting via RFI in Web Management Interface
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2024-20405. PoCs published by 3zz4t.
AI-analyzed exploit summary This repository provides a functional proof-of-concept for CVE-2024-20405, demonstrating a stored XSS attack via RFI in Cisco Finesse's web-based management interface. The PoC includes detailed steps to create a malicious XML configuration file, host it locally, and craft an HTTP request to exploit the vulnerability.
Description
A vulnerability in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker to conduct a stored XSS attack by exploiting an RFI vulnerability. This vulnerability is due to insufficient validation of user-supplied input for specific HTTP requests that are sent to an affected device. An attacker could exploit this vulnerability by persuading a user to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive information on the affected device.
Exploits (1)
This repository provides a functional proof-of-concept for CVE-2024-20405, demonstrating a stored XSS attack via RFI in Cisco Finesse's web-based management interface. The PoC includes detailed steps to create a malicious XML configuration file, host it locally, and craft an HTTP request to exploit the vulnerability.
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N