Cross-site request forgery in Cisco Prime Infrastructure and Evolved Programmable Network (EPN) Manager - CVE-2023-20130
Published: April 6, 2023
Cisco Prime Infrastructure
Evolved Programmable Network (EPN) Manager
Cisco Systems, Inc
Description
The vulnerability allows a remote attacker to perform cross-site request forgery attacks.
The vulnerability exists due to insufficient validation of the HTTP request origin in the web-based management interface. A remote attacker can trick the victim to visit a specially crafted web page and obtain privileged information and conduct cross-site scripting (XSS) and cross-site request forgery (CSRF) attacks.