First published: Wed Aug 19 2015(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in Cisco Finesse 10.5(1) allow remote attackers to inject arbitrary web script or HTML via unspecified parameters in a (1) GET or (2) POST request, aka Bug IDs CSCuq82322, CSCut95853, and CSCuq73975.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Finesse | =10.5\(1\)_base |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-4310 is classified as a high-severity vulnerability due to its potential for remote exploitation.
To mitigate CVE-2015-4310, update Cisco Finesse to the latest version that addresses these cross-site scripting vulnerabilities.
CVE-2015-4310 is a cross-site scripting (XSS) vulnerability that allows attackers to inject arbitrary web scripts or HTML.
CVE-2015-4310 affects Cisco Finesse version 10.5(1) and potentially other related applications.
Yes, CVE-2015-4310 can be exploited by remote attackers through simple scripting in GET or POST requests.