QID 316992
Date Published: 2021-09-29
QID 316992: Cisco Unified Contact Center Express Reflected Cross-Site Scripting Vulnerability(cisco-sa-cuic-xss-csHUdtrL)
A vulnerability in the web-based management interface of Cisco Unified Intelligence Center could allow an unauthenticated,
remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface.
Affected Products:
Cisco products that may be bundled with Cisco Unified Intelligence Center are also affected by this vulnerability:
Unified Contact Center Express (Unified CCX)
Unified Contact Center Enterprise (Unified CCE) (No Support)
Packaged Contact Center Enterprise (Packaged CCE)(No Support)
Vulnerable releases:
Prior to 12.5(1) SU2
QID Detection Logic(Authenticated):
It checks for vulnerable OS version of Cisco Unified Contact Center Express
A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface or access sensitive, browser-based information.
Customers are advised to refer to cisco-sa-cuic-xss-csHUdtrL for more information.
- cisco-sa-cuic-xss-csHUdtrL -
tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cuic-xss-csHUdtrL
CVEs related to QID 316992
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| cisco-sa-cuic-xss-csHUdtrL |
|