CVE-2015-0698: Cisco Web Security Appliance
Medium severity, CVSS 4.3. EPSS: 1.5% chance of exploitation in the next 30 days.
Multiple cross-site scripting (XSS) vulnerabilities in filter search forms in admin web pages on Cisco Web Security Appliance (WSA) devices with software 8.5.0-497 allow remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCut39213.
Affected products
- Cisco Web Security Appliance: up to and including 8.5.0-497
Published 2015-04-15. Last modified 2026-06-17.