First published: Wed Jul 10 2013(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in Cisco Unified Communications Domain Manager allow remote attackers to inject arbitrary web script or HTML via vectors involving the (1) IptAccountMgmt, (2) IptFeatureConfigTemplateMgmt, (3) IptFeatureDisplayPolicyMgmt, or (4) IptProviderMgmt page, aka Bug IDs CSCud69972, CSCud70193, and CSCud70261.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Unified Communications Domain Manager |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-1132 has a CVSS score indicating a medium severity due to the potential for remote code execution through XSS.
To fix CVE-2013-1132, apply the latest patches and updates provided by Cisco for the Unified Communications Domain Manager.
CVE-2013-1132 affects the Cisco Unified Communications Domain Manager and associated web management interfaces.
CVE-2013-1132 allows attackers to execute arbitrary web scripts or HTML, leading to potential phishing or data theft.
While there are no official workarounds for CVE-2013-1132, restricting access to the affected management interfaces may mitigate risk.