CVE-2018-0402: XSS
Published Jul 18, 2018
·Updated
Multiple vulnerabilities in the web-based management interface of Cisco Unified Contact Center Express (Unified CCX) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack. Cisco Bug IDs: CSCvg70921.
Affected Software
2 affected components
Cisco Unified Contact Center Express=11.5\(1\)
Cisco Unified Ip Interactive Voice Response=11.5\(1\)
Event History
Jul 18, 2018
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2018-0402?
The severity of CVE-2018-0402 is high.
2
What is the impact of CVE-2018-0402?
CVE-2018-0402 could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack.
3
How can an attacker exploit CVE-2018-0402?
An attacker can exploit CVE-2018-0402 by tricking a user into visiting a malicious website or clicking on a malicious link.
4
Is there a fix available for CVE-2018-0402?
Yes, Cisco has released a security advisory with fixes and mitigations for CVE-2018-0402.
5
Where can I find more information about CVE-2018-0402?
You can find more information about CVE-2018-0402 in the security advisory published by Cisco.