First published: Wed Apr 07 2021(Updated: )
A vulnerability in the web-based management interface of Cisco Unified Intelligence Center Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability exists because the web-based management interface does not properly validate user-supplied input. An attacker could exploit this vulnerability by persuading a user of an affected interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability. This advisory is available at the following link:https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cuic-xss-U2WTsUg6
Credit: security researcher Tarkan Digital
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Unified Intelligence Center | >=11.6(1) and earlier=12.0(1)<=12.5(1)<12.6(1) | 12.6(1) |
Cisco Unified Contact Center Express Enhanced | >=11.6(1) and earlier=12.0(1)<=12.5(1)<12.5(1) SU1 | 12.5(1) SU1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of cisco-sa-cuic-xss-U2WTsUg6 is considered important as it allows for cross-site scripting (XSS) attacks.
To fix cisco-sa-cuic-xss-U2WTsUg6, users should upgrade to the appropriate patched versions of Cisco Unified Intelligence Center and Cisco Unified Contact Center Express.
Cisco Unified Intelligence Center and Cisco Unified Contact Center Express releases prior to specific patched versions are affected by cisco-sa-cuic-xss-U2WTsUg6.
cisco-sa-cuic-xss-U2WTsUg6 allows unauthenticated remote attackers to conduct cross-site scripting (XSS) attacks.
No, exploitation of cisco-sa-cuic-xss-U2WTsUg6 does not require authentication, making it more dangerous.