cisco-sa-cucm-xss-9zmfHyZ: Cisco Unified Communications Manager Cross-Site Scripting Vulnerability
A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against
Affected Software
Event History
Frequently Asked Questions
What is the severity of cisco-sa-cucm-xss-9zmfHyZ?
The severity of cisco-sa-cucm-xss-9zmfHyZ is classified as high due to the potential for unauthenticated remote attackers to execute cross-site scripting attacks.
How do I fix cisco-sa-cucm-xss-9zmfHyZ?
To remediate cisco-sa-cucm-xss-9zmfHyZ, apply the latest security patches provided by Cisco for affected products.
Who is affected by cisco-sa-cucm-xss-9zmfHyZ?
Cisco Unified Communications Manager and Cisco Unified Communications Manager Session Management Edition users are affected by cisco-sa-cucm-xss-9zmfHyZ.
What type of attack can be performed due to cisco-sa-cucm-xss-9zmfHyZ?
Due to cisco-sa-cucm-xss-9zmfHyZ, attackers can conduct cross-site scripting (XSS) attacks via the web-based management interface.
Is authentication required to exploit cisco-sa-cucm-xss-9zmfHyZ?
No, authentication is not required to exploit cisco-sa-cucm-xss-9zmfHyZ, allowing unauthenticated attackers to conduct the exploit.