
[CIVN-2026-0070] Cross-Site Scripting vulnerability in CISCO
—–BEGIN PGP SIGNED MESSAGE—–
Hash: SHA256
Cross-Site Scripting vulnerability in CISCO
Indian – Computer Emergency Response Team (https://www.cert-in.org.in)
Severity Rating: MEDIUM
Systems Affected
Cisco Prime Infrastructure
Overview
A vulnerability has been reported in web-based management interface of Cisco Prime Infrastructure could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against users of the interface of an affected system.
Target Audience:
All IT administrators and individuals responsible for maintaining and updating in Software.
Risk Assessment:
High risk of data manipulation and service disruption.
Impact Assessment:
Potential impact on confidentiality, integrity, and availability of the system.
Description
This vulnerability exists due to web-based management interface does not properly validate user-supplied input. An attacker could exploit this vulnerability by inserting malicious code into specific data fields in the interface.
Successful exploitation of this vulnerability could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information.
Solution
Apply appropriate updates as mentioned in Cisco Advisory
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-pi-xss-bYeVKCD
Vendor Information
CISCO
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-pi-xss-bYeVKCD
References
CISCO
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-pi-xss-bYeVKCD
CVE Name
CVE-2026-20111
– —
Thanks and Regards,
CERT-In
Incident Response Help Desk
e-mail: incident@cert-in.org.in
Phone: +91-11-22902657
Toll Free Number: 1800-11-4949
Toll Free Fax : 1800-11-6969
Web: http://www.cert-in.org.in
PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4
PGP Key information:
https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS
Postal address:
Indian Computer Emergency Response Team (CERT-In)
Ministry of Electronics and Information Technology
Government of India
Electronics Niketan
6, C.G.O. Complex
New Delhi-110 003
—–BEGIN PGP SIGNATURE—–
iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmmG8jkACgkQ3jCgcSdc
ys/7/Q/+PfMX3nrO76IgK8dLkh0iFojN4evaZT2bq3MX+1JgdP3nwX7C4XXLJVBI
UWBcxYx6dZPqQXRxIBJ9RqRRqBACt3bbpN50U9WgPcNH0Yw6lmVFkhvCLXWRnFyf
Xzph5sTpYxhaxJ0115U5RNeZfU/DuxuNxOZaQS2IXKIbDFOMxCvCh7Dq1dlDwgi5
JcgIppgYnocPNFlpOiLjWlL0tpL+23iYAy5M5alSwn9965wi/vS1vi/wWuXrjjLk
AGeA/eJhUmz3zJPM81Hixwjhk6EoLcOHaakG18dDO9LsimXio/Lm3kq2w96eaEB/
PEsRcLHIOHBGQbcR7O1x/nMHXQBCE+d/le6IIt+SK6zrLZMjLYHxNvGq1tEjCQdR
/YSthbra1D283VgSeqnY3g3nPJTWNDoc9pyfNBmpqMcOqcuD7VvaNpWBeMO+Tqbc
ZXU9kYhCL+jgiJvvvAcX/2hcvh4p9FNozC2mymOOfh7Nqem1ARPulMsDyo3DEX9X
IZDBMhAaCYwKYwvpI15Fvmypkquhd39y579DqNJNQYBRjwMYtjx+BWwXdP3LaqCj
4pRSBRXnBySNGcD5UWgMCojGFkvw4T+aek7hWkrPSkrxJqbzntca8wH759y/aiq+
dntrCgiRmuh/+RwYwV/T+qJY9AccUx/WtJv32qB1kWWsN4D/3+Q=
=YFew
—–END PGP SIGNATURE—–


