First published: Tue Jul 14 2015(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in the ccmivr page in Cisco Unified Communications Manager (formerly CallManager) 10.5(2.10000.5) allow remote attackers to inject arbitrary web script or HTML via a crafted parameter, aka Bug ID CSCut19580.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Unified Communications Manager | =10.5\(2.10000.5\) |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-4272 is classified as a high severity vulnerability due to its potential to allow remote attackers to execute arbitrary web scripts.
Fixing CVE-2015-4272 involves applying the latest security updates provided by Cisco for Unified Communications Manager version 10.5(2.10000.5).
The potential impacts of CVE-2015-4272 include unauthorized data access and session hijacking due to cross-site scripting attacks.
CVE-2015-4272 specifically affects Cisco Unified Communications Manager version 10.5(2.10000.5) and may not be present in newer versions that have addressed these vulnerabilities.
Yes, CVE-2015-4272 can be exploited remotely by attackers through crafted parameters to inject web scripts.