Cisco Identity Services Engine Infra Admin User Interface Cross-Site Scripting Vulnerability
Description
A vulnerability has been identified in administrative user interface of Cisco Identity Services Engine.
A remote attacker can exploit it by enticing their victim into following a specially crafted link in order to execute arbitrary JavaScript or HTML code.
This vulnerability is located in the "selectedItemName" parameter of the "/admin/supportBundleAction.do" web page.
Cisco announces that a private exploitation code exists.