First published: Wed Jan 27 2016(Updated: )
Cross-site scripting (XSS) vulnerability in Cisco Unity Connection (UC) 10.5(2.3009) allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCux82582.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Unity Connection | =10.5\(2.3009\) |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-1300 has been rated as a medium severity vulnerability due to its potential for exploitation via XSS attacks.
To mitigate CVE-2016-1300, upgrade Cisco Unity Connection to a version that has addressed this vulnerability.
CVE-2016-1300 can be exploited through cross-site scripting (XSS), allowing attackers to inject malicious scripts.
CVE-2016-1300 affects users of Cisco Unity Connection version 10.5(2.3009).
Yes, CVE-2016-1300 can be exploited remotely by attackers through crafted URLs.