CVE-2016-1298: XSS
Multiple cross-site scripting (XSS) vulnerabilities in Cisco Unified Contact Center Express 10.0(1), 10.5(1), 10.6(1), and 11.0(1) allow remote attackers to inject arbitrary web script or HTML via vectors related to permalinks, aka Bug ID CSCux92033.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-1298?
CVE-2016-1298 has a high severity rating due to its potential for remote code execution via cross-site scripting.
How do I fix CVE-2016-1298?
To fix CVE-2016-1298, update your Cisco Unified Contact Center Express to a patched version as provided by Cisco.
What are the affected versions for CVE-2016-1298?
CVE-2016-1298 affects Cisco Unified Contact Center Express versions 10.0(1), 10.5(1), 10.6(1), and 11.0(1).
What types of vulnerabilities are associated with CVE-2016-1298?
CVE-2016-1298 is associated with multiple cross-site scripting (XSS) vulnerabilities that allow remote attackers to inject harmful scripts.
Can CVE-2016-1298 be exploited remotely?
Yes, CVE-2016-1298 can be exploited remotely, allowing attackers to inject arbitrary web scripts or HTML.