CVE-2018-0401: XSS
Multiple vulnerabilities in the web-based management interface of Cisco Unified Contact Center Express (Unified CCX) could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. Cisco Bug IDs: CSCvg70967.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-0401?
CVE-2018-0401 has been rated as having a high severity due to the potential for cross-site scripting attacks.
How do I fix CVE-2018-0401?
To fix CVE-2018-0401, update your Cisco Unified Contact Center Express and Cisco IP Interactive Voice Response software to the latest version recommended by Cisco.
Who is affected by CVE-2018-0401?
CVE-2018-0401 affects users of Cisco Unified Contact Center Express version 11.5(1) and Cisco IP Interactive Voice Response 11.5(1).
What types of attacks can be conducted due to CVE-2018-0401?
CVE-2018-0401 could allow an unauthenticated remote attacker to conduct cross-site scripting (XSS) attacks against users of the web-based management interface.
Is authentication required to exploit CVE-2018-0401?
No, CVE-2018-0401 can be exploited by an unauthenticated attacker, making it particularly dangerous.