云虫漏洞库

CVE-2026-20087 - A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with administrative privileges to conduct a stored XSS attack against a user of the interface. This vulnerability is due to insufficient validation of user input. An attacker could exploit this vulnerability by persuading a user of an affected interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the br - 漏洞详情

漏洞编号:CVE-2026-20087

风险等级:中危

漏洞来源:CVE

CVE 编号:CVE-2026-20087

CNNVD 编号:-

厂商/产品:cisco / enterprise_nfv_infrastructure_software

影响范围:cpe:2.3:a:cisco:enterprise_nfv_infrastructure_software:3.3.1:*:*:*:*:*:*:*

CWE:CWE-79

发布/更新时间:2026-04-01 / 2026-08-28

漏洞描述

A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with administrative privileges to conduct a stored XSS attack against a user of the interface.

This vulnerability is due to insufficient validation of user input. An attacker could exploit this vulnerability by persuading a user of an affected interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the browser of the targeted user or access sensitive, browser-based information.

相关链接

相关漏洞

« 返回首页