Cross-Site Scripting Vulnerability in Cisco Unified Web and E-Mail Interaction Manager
CVE-2015-6255

Currently unrated

Key Information:

Vendor
Cisco
Vendor
CVE Published:
19 August 2015

Summary

A cross-site scripting vulnerability exists in Cisco Unified Web and E-Mail Interaction Manager 9.0(2), which enables remote attackers to inject arbitrary web scripts or HTML through specially crafted chat messages. This flaw can lead to various security issues, including session hijacking and unwanted actions performed on behalf of unsuspecting users.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.