VDB

CISCO-SA-VMANAGE-HTML-INJ-GXVTK6ZJ

CISCO-SA-VMANAGE-HTML-INJ-GXVTK6ZJ PUBLISHED CVSS 4.699999809265137 MEDIUM

A vulnerability in the web interface of Cisco Catalyst SD-WAN Manager, formerly Cisco SD-WAN vManage, could allow an unauthenticated, remote attacker to inject HTML into the browser of an authenticated user. This vulnerability is due to improper sanitization of input to the web interface. An attacker could exploit this vulnerability by convincing an authenticated user to click a malicious link. A successful exploit could allow the attacker to inject HTML into the browser of an authenticated Cisco Catalyst SD-WAN Manager user. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.

Risk Scores

CVSS v3.1
4.699999809265137
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N

Affected Products

VendorProductVersions
Cisco Catalyst SD-WAN Manager

Timeline

  • May 7, 2025 CVE Published
Open in Interactive Console →
$ Console Community · 100/wk Open console ›