CVE-2012-6007
Cross-site scripting (XSS) vulnerability in screens/base/web_auth_custom.html on Cisco Wireless LAN Controller (WLC) devices with software 7.2.110.0 allows remote authenticated users to inject arbitrary web script or HTML via the headline parameter, aka…
Does this matter?
Lower severity and a low EPSS score (3.66%). Track it; it rarely justifies an emergency change on its own.
Description
Cross-site scripting (XSS) vulnerability in screens/base/web_auth_custom.html on Cisco Wireless LAN Controller (WLC) devices with software 7.2.110.0 allows remote authenticated users to inject arbitrary web script or HTML via the headline parameter, aka Bug ID CSCud65187, a different vulnerability than CVE-2012-5992.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
- EPSS
- 3.66% probability · 89th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- cisco/wireless lan controller software · cisco/2000 wireless lan controller · cisco/2100 wireless lan controller · cisco/2500 wireless lan controller · cisco/4100 wireless lan controller · cisco/4400 wireless lan controller · cisco/5500 wireless lan controller · cisco/7500 wireless lan controller · cisco/8500 wireless lan controller
- Source
- psirt@cisco.com
References
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.