#VU51975 Link Injection in Cisco Umbrella - CVE-2021-1475
Published: April 8, 2021
Cisco Umbrella
Cisco Systems, Inc
Description
The vulnerability allows a remote attacker to compromise the target system.
The vulnerability exists due to improper neutralization of user-supplied input in the Scheduled Reports feature. A remote authenticated attacker can inject a malicious link into the report, leading the user to believe that the link is coming from the application.