A vulnerability in the web framework of Cisco Emergency Responder Software could allow an unauthenticated, remote attacker to execute a stored cross-site scripting (XSS) attack against the user of the web interface.

The vulnerability is due to  insufficient validation on the input fields of a web form. An attacker could exploit this vulnerability by entering malicious code in an affected form that is then stored in the database.

Cisco has not released software updates that address this vulnerability. Workarounds that mitigate this vulnerability are not available.

This advisory is available at the following link: http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20151210-cer

Leave a Reply