Cisco Identity Services Engine Cross-Site Scripting Vulnerability
Cisco patched a reflected XSS in the ISE management interface allowing unauthenticated attackers to execute script via crafted links.
A reflected cross-site scripting vulnerability in the web-based management interface of Cisco Identity Services Engine lets an unauthenticated remote attacker execute arbitrary script in the context of the interface. Exploitation requires persuading a user to click a crafted link due to improper input validation. Cisco has released software updates.