ZeroHour

CVE-2023-20181

CVSS 3.1
6.1 medium
EPSS
<1%p43
Published
()
Modified
Description

A vulnerability in the web-based management interface of Cisco Small Business SPA500 Series IP Phones could allow an unauthenticated, remote attacker to conduct XSS attacks. This vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of the affected software. An attacker could exploit this vulnerability by persuading a user to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information.

Vendors
cisco
Products
spa500ds firmware, spa500s firmware, spa501g firmware, spa502g firmware, spa504g firmware, spa508g firmware, spa509g firmware, spa512g firmware, spa514g firmware, spa525 firmware, spa525g firmware, spa525g2 firmware
Weakness
CWE-80, CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.