Description
Cross-site scripting vulnerability in CiscoSecure ACS 3.0 allows remote attackers to execute arbitrary script or HTML as other web users via the action argument in a link to setup.exe.
Affected products
- Cisco / secure_access_control_server3.0 – 3.0
- Cisco / secure_access_control_server3.0.1 – 3.0.1