CVE-2014-8018: XSS
Multiple cross-site scripting (XSS) vulnerabilities in Business Voice Services Manager (BVSM) pages in the Application Software in Cisco Unified Communications Domain Manager 8 allow remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug IDs CSCur19651, CSCur18555, CSCur19630, and CSCur19661.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-8018?
CVE-2014-8018 is classified as a high severity vulnerability due to its potential for allowing remote attackers to exploit cross-site scripting flaws.
How do I fix CVE-2014-8018?
To mitigate CVE-2014-8018, users should apply the latest security patches provided by Cisco for the affected version of Unified Communications Domain Manager.
What systems are affected by CVE-2014-8018?
CVE-2014-8018 affects Cisco Unified Communications Domain Manager version 8.0 and related Business Voice Services Manager pages.
What kind of attacks can be executed using CVE-2014-8018?
CVE-2014-8018 allows attackers to inject arbitrary web script or HTML, potentially leading to data theft or session hijacking.
Are there any workarounds for CVE-2014-8018?
As a workaround for CVE-2014-8018, it is recommended to restrict access to the vulnerable pages until the proper security updates are applied.