CVE-2016-1354: XSS
Cross-site scripting (XSS) vulnerability in Cisco Unified Communications Domain Manager (UCDM) 8.x before 8.1.1 allows remote attackers to inject arbitrary web script or HTML via crafted markup data, aka Bug ID CSCud41176.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-1354?
CVE-2016-1354 is classified as a high severity vulnerability due to the potential for remote code execution via cross-site scripting.
How do I fix CVE-2016-1354?
To fix CVE-2016-1354, upgrade Cisco Unified Communications Domain Manager to version 8.1.1 or later.
What systems are affected by CVE-2016-1354?
CVE-2016-1354 affects Cisco Unified Communications Domain Manager versions 8.0, 8.0.1, and 8.0.2.
Can CVE-2016-1354 be exploited remotely?
Yes, CVE-2016-1354 can be exploited remotely, allowing attackers to execute scripts in the context of the user's session.
What type of vulnerability is CVE-2016-1354?
CVE-2016-1354 is a cross-site scripting (XSS) vulnerability that allows injection of arbitrary web script or HTML.