CVE-2015-4294: XSS
Cross-site scripting (XSS) vulnerability in Cisco IM and Presence Service before 10.5 MR1 allows remote attackers to inject arbitrary web script or HTML by constructing a crafted URL that leverages incomplete filtering of HTML elements, aka Bug ID CSCut41766.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-4294?
CVE-2015-4294 is classified as a medium severity cross-site scripting vulnerability.
How do I fix CVE-2015-4294?
To fix CVE-2015-4294, upgrade to a version of Cisco IM and Presence Service that is 10.5 MR1 or later.
What software is affected by CVE-2015-4294?
CVE-2015-4294 affects Cisco Unified Communications Manager IM and Presence Service versions 9.0(1), 9.1(1), and 10.5(1) before the specified updates.
Can CVE-2015-4294 lead to unauthorized access?
Yes, CVE-2015-4294 could allow remote attackers to inject arbitrary web scripts or HTML, potentially leading to unauthorized actions.
Is CVE-2015-4294 exploitable over the internet?
Yes, CVE-2015-4294 can be exploited by attackers with access to the vulnerable Cisco IM and Presence Service over the internet.