cisco-sa-cuic-xss-csHUdtrL: Cisco Unified Intelligence Center Reflected Cross-Site Scripting Vulnerability
A vulnerability in the web-based management interface of Cisco Unified Intelligence Center could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability exists because the web-based management interface does not properly validate user-supplied input. An attacker could exploit this vulnerability by persuading a user of the interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface or access sensitive, browser-based information. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability. This advisory is available at the following link:https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cuic-xss-csHUdtrL
Credit
Affected Software
Event History
Frequently Asked Questions
What is the Cisco Unified Intelligence Center Reflected Cross-Site Scripting vulnerability?
The vulnerability allows an attacker to conduct a cross-site scripting (XSS) attack against a user of the interface.
What is the severity of the Cisco Unified Intelligence Center Reflected Cross-Site Scripting vulnerability?
The severity of this vulnerability is medium, with a CVSS score of 6.1.
Which software versions are affected by the Cisco Unified Intelligence Center Reflected Cross-Site Scripting vulnerability?
The affected software versions are 12.5(1) ES7, 12.0(1) ES14, 11.6(1) and earlier, and 12.0(1) to 12.0(1) ES14.
How can I fix the Cisco Unified Intelligence Center Reflected Cross-Site Scripting vulnerability?
To fix the vulnerability, upgrade to Cisco Unified Intelligence Center version 12.5(1) ES7, 12.5(1) SU2, or later.
What is the Common Weakness Enumeration (CWE) ID associated with the Cisco Unified Intelligence Center Reflected Cross-Site Scripting vulnerability?
The CWE ID associated with this vulnerability is CWE-79.