QID 317446
QID 317446: Cisco Unified Communications Manager IM and Presence Service Cross-Site Scripting (XSS) Vulnerability (cisco-sa-cucm-imps-xss-quWkd9yF)
A vulnerability in the web-based interface of Cisco Unified Communications Manager IM and Presence Service (Unified CM IM and P) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against an authenticated user of the interface.
Affected Products:
Cisco Unified Communications Manager IM and Presence Service Release
Prior to version 12.5 SU8
Prior to version 14 SU4
QID Detection Logic (Authenticated):
The check matches the Cisco Unified Communications Product version retrieved via Unix Auth using " Active Master Version:" command.
A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive browser-based information.
Customers are advised to refer to cisco-sa-cucm-imps-xss-quWkd9yF for more information.
- cisco-sa-cucm-imps-xss-quWkd9yF -
sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cucm-imps-xss-quWkd9yF
CVEs related to QID 317446
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| cisco-sa-cucm-imps-xss-quWkd9yF |
|