CVE-2023-20060 is a cross-site scripting (XSS) vulnerability in the web-based management interface of Cisco Prime Collaboration Deployment. An unauthenticated, remote attacker can exploit this flaw by tricking a user into clicking a crafted link, leading to arbitrary script execution or sensitive information disclosure. With a CVSS score of 6.1 (Medium), this vulnerability has a low attack complexity and requires user interaction. While Cisco plans to release updates, there are no known workarounds, and there is no public exploit code or evidence of active exploitation, though it has garnered significant community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 14su3CPE matchmatch criteria | cpe:2.3:a:cisco:prime_collaboration_deployment:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.