First published: Tue Apr 12 2016(Updated: )
Cross-site scripting (XSS) vulnerability in Cisco Unity Connection through 11.0 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters, aka Bug ID CSCus21776.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Unity Connection | =10.0.0 | |
Cisco Unity Connection | =10.0.5 | |
Cisco Unity Connection | =10.5\(2\) | |
Cisco Unity Connection | =10.5\(2.3009\) | |
Cisco Unity Connection | =11.0\(0.98000.225\) | |
Cisco Unity Connection | =11.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-1377 is considered a moderate severity vulnerability due to its potential for cross-site scripting attacks.
To fix CVE-2016-1377, upgrade your Cisco Unity Connection to a version that includes the patched code, as indicated by Cisco's advisory.
CVE-2016-1377 affects Cisco Unity Connection versions 10.0.0, 10.0.5, 10.5(2), 10.5(2.3009), 11.0(0.98000.225), and 11.0.0.
CVE-2016-1377 is a cross-site scripting (XSS) vulnerability that allows remote attackers to inject arbitrary web scripts or HTML.
Yes, CVE-2016-1377 can be exploited remotely, allowing unauthorized users to perform actions via malicious scripts.