First published: Thu Mar 03 2016(Updated: )
Cross-site scripting (XSS) vulnerability in Cisco Unified Communications Domain Manager (UCDM) 8.x before 8.1.1 allows remote attackers to inject arbitrary web script or HTML via crafted markup data, aka Bug ID CSCud41176.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Unified Communications Domain Manager | =8.0 | |
Cisco Unified Communications Domain Manager | =8.0.1 | |
Cisco Unified Communications Domain Manager | =8.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-1354 is classified as a high severity vulnerability due to the potential for remote code execution via cross-site scripting.
To fix CVE-2016-1354, upgrade Cisco Unified Communications Domain Manager to version 8.1.1 or later.
CVE-2016-1354 affects Cisco Unified Communications Domain Manager versions 8.0, 8.0.1, and 8.0.2.
Yes, CVE-2016-1354 can be exploited remotely, allowing attackers to execute scripts in the context of the user's session.
CVE-2016-1354 is a cross-site scripting (XSS) vulnerability that allows injection of arbitrary web script or HTML.