CVE-2017-12321 describes multiple cross-site scripting (XSS) and URL redirection vulnerabilities within the web interface of the Cisco Registered Envelope Service, a cloud-based offering. These flaws stem from insufficient validation of user-supplied input. An unauthenticated, remote attacker could exploit these by tricking a user into clicking a malicious link or sending a crafted HTTP request. The vulnerability has a CVSS v3.0 score of 6.1 (Medium), indicating a network-based attack vector with low attack complexity, requiring user interaction. Successful exploitation could lead to arbitrary script execution in the user's browser context, access to sensitive browser-based information, or redirection to malicious websites, potentially facilitating phishing attacks. There is no evidence of active exploitation, nor is there publicly available exploit code in frameworks like Metasploit or ExploitDB. Community discussion and media coverage for this CVE are minimal, suggesting it has not garnered significant attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:cisco:registered_envelope_service:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.