CVE-2013-1132: XSS
Multiple cross-site scripting (XSS) vulnerabilities in Cisco Unified Communications Domain Manager allow remote attackers to inject arbitrary web script or HTML via vectors involving the (1) IptAccountMgmt, (2) IptFeatureConfigTemplateMgmt, (3) IptFeatureDisplayPolicyMgmt, or (4) IptProviderMgmt page, aka Bug IDs CSCud69972, CSCud70193, and CSCud70261.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-1132?
CVE-2013-1132 has a CVSS score indicating a medium severity due to the potential for remote code execution through XSS.
How do I fix CVE-2013-1132?
To fix CVE-2013-1132, apply the latest patches and updates provided by Cisco for the Unified Communications Domain Manager.
What systems are affected by CVE-2013-1132?
CVE-2013-1132 affects the Cisco Unified Communications Domain Manager and associated web management interfaces.
What types of attacks can be executed through CVE-2013-1132?
CVE-2013-1132 allows attackers to execute arbitrary web scripts or HTML, leading to potential phishing or data theft.
Is there a workaround for CVE-2013-1132 if I cannot apply the patch immediately?
While there are no official workarounds for CVE-2013-1132, restricting access to the affected management interfaces may mitigate risk.