Cisco Common Services Platform Collector Cross-Site Scripting Vulnerability

Vulnerability

A cross-site scripting (XSS) vulnerability has been identified in the web-based management interface of Cisco Common Services Platform Collector (CSPC). This vulnerability allows an authenticated, remote attacker to conduct XSS attacks against users of the interface. The issue arises from insufficient validation of user-supplied input, enabling attackers to inject malicious code into specific pages. Exploitation of this vulnerability could result in the execution of arbitrary scripts in the context of the affected interface or access to sensitive browser-based information. To exploit this vulnerability, an attacker must have at least a low-privileged account on the affected device.

Impact

Exploitation of this vulnerability could allow an attacker to execute arbitrary scripts in the context of the affected interface or access sensitive browser-based information.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
2.6
impact
3.1
exploitability
4.6
remediation
0.0
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.