PT-2019-2130 · Cisco · Cisco Registered Envelope Service

Rahul Raj

·

Published

2019-04-17

·

Updated

2023-03-01

·

CVE-2019-1777

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Cisco Registered Envelope Service versions 5.3.4.x
Description The issue is related to insufficient validation of user-supplied input by the web-based interface, allowing an attacker to conduct a cross-site scripting (XSS) attack. This could enable the execution of arbitrary script code or access to sensitive information by sending a specially crafted email.
Recommendations For versions 5.3.4.x, update to a version that includes the fix for this issue to prevent exploitation. As a temporary workaround, consider restricting access to the web-based interface of the Cisco Registered Envelope Service to minimize the risk of exploitation. Avoid using the service to send or receive sensitive information until the issue is resolved.

Fix

XSS

Weakness Enumeration

Related Identifiers

BDU:2019-01891
CVE-2019-1777

Affected Products

Cisco Registered Envelope Service