Cross-Site Scripting Vulnerability in Cisco Unified Web and E-Mail Interaction Manager
CVE-2015-6255
Currently unrated
Key Information:
- Vendor
- Cisco
- Vendor
- CVE Published:
- 19 August 2015
Summary
A cross-site scripting vulnerability exists in Cisco Unified Web and E-Mail Interaction Manager 9.0(2), which enables remote attackers to inject arbitrary web scripts or HTML through specially crafted chat messages. This flaw can lead to various security issues, including session hijacking and unwanted actions performed on behalf of unsuspecting users.
References
Timeline
Vulnerability published
Vulnerability Reserved