Cisco IMC
cpe:2.3:a:cisco:integrated_management_controller:*:*:*:*:*:*:*
A stored cross-site scripting vulnerability has been identified in the web-based management interface of Cisco Integrated Management Controller (IMC). This issue allows an authenticated, remote attacker with administrative privileges to execute arbitrary script code in the browser of a user interacting with the interface, or to access sensitive browser-based information. The vulnerability arises from inadequate validation of user input, enabling attackers to craft links that, when clicked by the user, trigger the execution of malicious scripts.
Exploitation of this vulnerability could lead to stored cross-site scripting, where injected scripts are executed in the context of the user.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.