QID 317321

Date Published: 2023-05-24

QID 317321: Cisco Unified Contact Center Express Stored Cross-Site Scripting (XSS) Vulnerability (cisco-sa-uccx-xss-GO9L9xxr)

A vulnerability in the web-based management interface of Cisco Unified Intelligence Center could allow an unauthenticated,
remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface.

Vulnerable releases:
Prior to 12.5(1)SU3

QID Detection Logic(Authenticated):
It checks for vulnerable OS version of Cisco Unified Contact Center Express.

A successful exploit could allow allow an authenticated, remote attacker to perform a stored cross-site scripting (XSS) attack.

  • CVSS V3 rated as Medium - 5.4 severity.
  • CVSS V2 rated as Medium - 4.3 severity.
  • Solution

    Customers are advised to refer to cisco-sa-uccx-xss-GO9L9xxr for more information.

    CVEs related to QID 317321

    Software Advisories
    Advisory ID Software Component Link
    cisco-sa-uccx-xss-GO9L9xxr URL Logo sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-uccx-xss-GO9L9xxr