CVE-2015-4272: XSS
Multiple cross-site scripting (XSS) vulnerabilities in the ccmivr page in Cisco Unified Communications Manager (formerly CallManager) 10.5(2.10000.5) allow remote attackers to inject arbitrary web script or HTML via a crafted parameter, aka Bug ID CSCut19580.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-4272?
CVE-2015-4272 is classified as a high severity vulnerability due to its potential to allow remote attackers to execute arbitrary web scripts.
How do I fix CVE-2015-4272?
Fixing CVE-2015-4272 involves applying the latest security updates provided by Cisco for Unified Communications Manager version 10.5(2.10000.5).
What are the potential impacts of CVE-2015-4272?
The potential impacts of CVE-2015-4272 include unauthorized data access and session hijacking due to cross-site scripting attacks.
Is CVE-2015-4272 present in newer versions of Cisco Unified Communications Manager?
CVE-2015-4272 specifically affects Cisco Unified Communications Manager version 10.5(2.10000.5) and may not be present in newer versions that have addressed these vulnerabilities.
Can CVE-2015-4272 be exploited remotely?
Yes, CVE-2015-4272 can be exploited remotely by attackers through crafted parameters to inject web scripts.