QID 316992

Date Published: 2021-09-29

QID 316992: Cisco Unified Contact Center Express Reflected Cross-Site Scripting Vulnerability(cisco-sa-cuic-xss-csHUdtrL)

A vulnerability in the web-based management interface of Cisco Unified Intelligence Center could allow an unauthenticated,
remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface.

Affected Products:
Cisco products that may be bundled with Cisco Unified Intelligence Center are also affected by this vulnerability:
Unified Contact Center Express (Unified CCX)
Unified Contact Center Enterprise (Unified CCE) (No Support)
Packaged Contact Center Enterprise (Packaged CCE)(No Support)

Vulnerable releases:
Prior to 12.5(1) SU2

QID Detection Logic(Authenticated):
It checks for vulnerable OS version of Cisco Unified Contact Center Express

A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface or access sensitive, browser-based information.

  • CVSS V3 rated as High - 6.1 severity.
  • CVSS V2 rated as Medium - 4.3 severity.
  • Solution

    Customers are advised to refer to cisco-sa-cuic-xss-csHUdtrL for more information.

    CVEs related to QID 316992

    Software Advisories
    Advisory ID Software Component Link
    cisco-sa-cuic-xss-csHUdtrL URL Logo tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cuic-xss-csHUdtrL