CVE-2024-20475 Information
Sep 26, 2024
cve
Description
A vulnerability in the web-based management interface of Cisco Catalyst SD-WAN Manager formerly Cisco SD-WAN vManage could allow an authenticated remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface.
This vulnerability exists because the web-based management interface does not properly validate user-supplied input. An attacker could exploit this vulnerability by inserting malicious data into a specific data field in an affected interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface.